Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev

Index digest:

sha256:72dd3501a24df8f40e522df6c80514300b82eed0a5c995fbb6210805e0c5b5d6

Manifest digest:

sha256:f289c3c3b6dd8cbbb084ccbd40ad9f542521e0e586751d35f03d217bae818a7d

Size

107.51 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:7bf4f270ad7ff70aa1b0e107a1dce6a704e17b462a0b8388fc9038c2d6010e26
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:9fdbf1267b17aefe5886d6bb02e994d5534d138a6abf6e42b7382bc54612aed8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-db@sha256:0102388d8f54d3bb47fdd7cf94348f8b15480fe5982ffc80b3e0aef6c26be082
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:aa0cfcdb6b615707e722617bdfe7184184592eb85b86d2ae3708072fa1d78253
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-db@sha256:72a6bfedb0135bac31ad9f7f50c354b7800d1b99ffd4f2132eb0146c4d4f2146
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:eb5fbdfe637da62e68841cfe875c16cebfc342cd3742b3d5f5d8862aa76badd8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:5e0bfd6bd3d2825120d869fd4ef9a64e67567e1e1ebdeb19ff9dee31700f6754
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:26515db3cf9f3c788d1be8d402e6d682002683bc2bf9aaf7939c88df29b42f8c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:1de0f5d7e6e485a10939be9492b8e86d077b005a427b9b46df718e29fd4dab5c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:f76817e646b8123f896dad817478cf0eb642d228f8c3d633fa7a3acc5310c26e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:0432241db9a3276d8f64a9602c3c74c7acadfcc4f81bee5bf63ece7271b34125
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:1dc70d7492bfc9ffccf3d2ede008021dbbefaa102f03800700d47e38af21dae0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:f3744917ede4f0e534391957f16fe2907f796db3113c7b3936651014dd972ff1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:55dd1a1220ec8c4ac28a68c20f12a8f2d37a7fdfa01a7ab458a9827b56d3a0e3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:33371b5671b1a7907a1023e78e502b2795fff757151b9ee11cf69e151b4f4de4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:9433c2f13e9cfc24eef1d93be33e669113d79eb48fde572244b1015dc22119b0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:5bc59b10f640f63f3a8edb8130b9285239ee62f0ed257c728ee6af505bc95c0e