Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.13.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips, 2.13-debian13-fips, 2.13-fips, 2.13.5-debian-fips, 2.13.5-debian13-fips, 2.13.5-fips

Index digest:

sha256:0ab2e3b258c5a2b5541c1188c4259ef5d1a6bef519ac6ee8a5e5c8cb0f621ba4

Manifest digest:

sha256:eabe5705bc79615221c7ad692b98ff78b7c3d44d0994060ee4864eaadd739046

Size

97.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.13-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:9e53e0be77995f605c56dbf9cec4b4919a31c14322e1b6556b4af013fe5b9575
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:fd1258528a35035b587348bbdb6c7ba367970321f8725ee8cf24342ea6c9e185
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-db@sha256:039b52ce4bc01185997797bd5bc2d757a14a050cef41c325006288067a8936df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:0472febcf85cf863c87319f47f9beef7807167139e02d1442595a09b09c2f85b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-db@sha256:35efcad342568d9c5f81f8a0c6e1969bff87cc3b2ab62b2ef1f1622904c0e0a5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:61fe088156e991030261b2ac82c32410d651f09a9df33e6d6a82a740fb2cae64
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:43a25249e3cb154fb848d88e211e18c9225ecbfc3505638dd1e8d1dd3d11271f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:8c9d98784f05a92d1c8c1f1d5ca171817a10f811993f7d8121dd7199775e216c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:7e46722753e2fbe21c1d3ee5b2b7071a0e483b4f56c29b974e0c69622e92a361
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:ceeccdcce5f3804a86f45b93dfba10bbfa6c16ba9653d7fe6665e14908161962
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:a0c900ff5b05553e1299f545731ad25af022fee09e627e5e16cb15165669a8ef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:59214a59047a106f29ff464ed8ffac8cdb278c90aadce62090dad6b3c7dbe68b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:f856541c2b9c641a6d66868c8cbc0de110b63b757b30b3a36accc87215932d32
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:6a58c421d0ed17ba1e58b73567f9ccdcd1aa8ba912d0db03c15b6779f31afd63
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:99a4ab62e542ee49a1e1f7a4ec097d5ac08de2dafffc9bfad801e96efa3e1089
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:a46d7e5225903e1fb57cc4657151fd2f834c63d84144772f56dae1bd9b043f3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:4a5d45da84f9b957ec1d083d923ca32993f9847d2fe251d391e267d0e95d8525