dhi.io/harbor-db
2.13-debian-fips, 2.13-debian13-fips, 2.13-fips, 2.13.6-debian-fips, 2.13.6-debian13-fips, 2.13.6-fips
sha256:6b4d9a5297a33bc6ea1112211bb6415ace95f15a2014e12960211a4199e289de
Manifest digest:sha256:48bcf67254aee08c59cd10ea48ce68d40454f5438be783b04272c40320a4c8b8
Size
97.43 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-db:2.13-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-db:2.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-db@sha256:6db5051056ce8cf15ae8081b913bf05a550a289ab77635eabb34c2193e427ed0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-db@sha256:9574808c7019d58f81eb687ba067e4acafaab6a5d5ecc7e2b5e48f10f450ee36 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-db@sha256:3d959a3eb4b2bb1b4a8be8ca5fa81895aaef08488a718f47c0046d2d378155f9 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-db@sha256:777d21d34fe1458f4f8e14f820d610c472e62ba2e50cc786f5affba6093ea72c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-db@sha256:9378c4fbe156bc34e4e97f6fd2ea5b42316e4956f019ba5b8a7e675605e7a6c6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-db@sha256:b31d941b44b047cc6156281a01ed13ea273d96d5791ca129089c5dbf0ab42e26 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-db@sha256:3403bdbd1c21c10c926db0364a4bb05bb538eb6b29225a1d661b645d564a99a1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-db@sha256:24aa28e200e49ab2403232e4f72ddadee55ffe97e6b31fc1933727626d6d7ffa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-db@sha256:62962177a9d4eacb7fd778dae5ffd7c175c02db76488bad8b2af33c7876fa611 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-db@sha256:b286d2867bd20ee3524bb3b177014a736c38f254655a2bdfaae9846e251af764 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-db@sha256:f99c773bea1c78885e6a3790f9ba16fbd43b71ccc61e2f489fa1dcacf21e4b4d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-db@sha256:39634158e2c98e6bc43b2225981bba769a4e28143df21f5abe47af6f9463dd39 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-db@sha256:d805b087b449a818cd6e57132103a3c23a3f732310ca52df1f9b0796029b3970 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-db@sha256:30a58d0cfdcf2125f3f5577d67cd3e58efd28d76dac2c7817fad6ab96222c690 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-db@sha256:595b5305810d4dcf801dbe46d6491be848c56cbaf12f5ad21014c9fff972932a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-db@sha256:74a26656e415b0f87afcfaf8fc0f28585002e9424c27131677792d6729e99fc7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-db@sha256:79d422a8f6080ef83206403c3efe961c16bd636d3d44af97b8d5e8278ad8fd8b |