Sign inSign up
Harbor Registry Control

dhi.io/harbor-registryctl

Harbor Registry Control 2.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.2-debian-dev, 2.15.2-debian13-dev, 2.15.2-dev

Index digest:

sha256:786fb4ff0bb33066bed09a11ed675e5d28289100001e89ff0ff6243ab5c2a158

Manifest digest:

sha256:4d88b4e90531dadd8ea0e8a937bc6f4f081834521b5babc57370d3630408d5cb

Size

39.00 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registryctl:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registryctl:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registryctl@sha256:4a52ab51346448bca61f3cae2cae95a61f98d08f70a90170922bf04828d9bba7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registryctl@sha256:e665bcc4df17da7184e97546f990c5ebd3b726a0915f87a68609149761ece894
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registryctl@sha256:5a57dc5f5f0758bf928d86483787b8b4691afe2cf6fcb6481cc2715d90224839
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registryctl@sha256:9bb912399232350808e6ec18f3ba63a7b4604ca3331dd1a3f3920f3bacee6e82
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registryctl@sha256:a186929eb0bacf1f399387f10121e2d68518a652ffea3a022e205c02d8f971da
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registryctl@sha256:dea35bdda3c89a4687b1e7080fafa6bf793e82624d0bedebe372c899b5c0f417
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registryctl@sha256:cbaeefb545fc31aaaab68aca6e38f65ac17f613384eb50d98494bf27d32725b0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registryctl@sha256:b4a262843d7e026aee27c507d089c82561b4fae176d607ad19ad78e212ecc386
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registryctl@sha256:aac1a8e6c5c1c39473392a956e33d07495ff47ed629171adfa9d1ddf718d04e5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registryctl@sha256:71b88fdff0ae9ff04c5967dc0572a066b5172b51475873704c2366ccc76227a4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registryctl@sha256:cbffbfdb2bfa5cbc847f06b35eeb6e5811dbee69ebd77ce01d2d3bcfd0d1176e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registryctl@sha256:ab2e5c9cfff4910f2650c065e8d05774946f0441a91eaf72bdc583e94371fc11
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registryctl@sha256:6d3a7c2a43886ee15878ebe08c04ca36b95568111c1b228791c99f5d76b4ef7c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registryctl@sha256:e43dd5b6f25f2ee1d7025541a6a7419c86c49dbe2de49b4529dbdd9145aa0248
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registryctl@sha256:ee45fee75bccb953c8aaedecf9ddea2791c63a6fbb52ea1a8d39e1a2612552cc