Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.14.x

CIS
linux/amd64
debian 13
Tags:

2.14, 2.14-debian, 2.14-debian13, 2.14.4, 2.14.4-debian, 2.14.4-debian13

Index digest:

sha256:b97e591753f90e7b08410b3316ca66aca9a94955feefe7183b8ba5e253239084

Manifest digest:

sha256:6a96a977e39e7079d3e5344084f171d6c4b78cb3343e9f6bdb52b0d74e3be142

Size

95.17 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:1c0a4a66cdc99a8d2275720471ede5e9d8c74e12c7d19a9c30a04550e060fa7c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:50f8c31fce66c4940e4bafec0051f973afa1b5672a496756904e2d183dc41076
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:2e7b51d41db8ed19026fb20141a8e0ad9baad95cc0aeb17a18e5a2b8252a61d1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:ef52a2eb3c2697f2ae03213ce86023bf0730b9d3cd5bb64cebc8cbf4d2820c3e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:401488d1eaa14aedcb673b67f1c719ae523fa2b18bd2e40d1d303558455d0b76
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:745a3b6e3e072382d585cdcb8234ecceb691e85c368d5ad1e47b69895cf3394e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:8d53598a76ecd88b05b0a20d7129510a2b5ef12386091e95a2639587fdbf935d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:4725611fca821163818b93efc20d06e6f31379db291b79b297bff22b5caaa117
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:9d0360b522214d0dbf611f0248152608736b3f0f1f07a2e4f08e92a12e2e93a4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:1f0aeeda99e576cfd67c66c6f0257cf3fc917434fd7604fec3d7c68bf3bff76f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:e59ccc8dc2722c1908387998bceacf4e7f722b5e225d6883c044a7d0c35af36a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:eddc1975323ef7b27094ddb90596d1752441f3cecb5f501a874138b41c32f3b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:7753e79cc6d5e4248c712a853319ff4a4fbe24b811f138ddb336d8545bde2435
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:3e2f67460d21e6e7238520ff9f6919a1d29a928e95e50c462c078302231d8fa0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:5ba06f97f727208585b2ec9f32f2f1a71432aa96cdc5c521c7459d1cf40fc713