Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.4-debian-fips-dev, 2.15.4-debian13-fips-dev, 2.15.4-fips-dev

Index digest:

sha256:661c81f6faf3bae1553133739b7e1f7e6fa6925e5cd201d3f9ee4c1da77b8625

Manifest digest:

sha256:03487ed93c43488d4c412a5f44c108380e218e4e13dbf3b9bfd27a12f14c63e1

Size

108.08 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:8ffb74f97b20ec7c42d8fc35f14b0efeca4dd12b611e6a75a6bf109293e6abe4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:6ee861fc2c929176079c562b31249509355137fc899efee5e07efe1d0e4ebb9c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-db@sha256:faafebf7d245b6731e9c043059997690dbd35a1fcc2018347eed23e8b6adb1d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:bbf7a526fbef40d18580f520d1a85f63b638d8edc2dd24c0091736f688b0abc1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-db@sha256:d46f386cbb83c0e3e0a7a4cefe2c50fc0d874b75d1ef36b832522ffd78961c38
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:5dc3e30621d2b55a60d0aae3b80cb87047f0907acca11fca0ef12bbdba6b4460
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:ef70139211c0558aa1fbbd8b5ff0925769ba32a3367e107ef8b9a2c49eab63ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:ff1e4a107fd310f24afab8b4ebecea8a81420fcf11d9aed4d1b2314f34d264ec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:dbbfa5da0d92c392dca96fc9e0b7d9545d46f70024e8b11e4a0079fcf224221a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:5c200e0ea2677472d5942797d77fe847b1b261f6c604e394fbbd33cafb546af8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:626d3c4043196e3aa2a3998fe409399662ef78cb9c74e7a684a749d53335fe8c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:ea52e2ad39bbf2abcd9d0bd381397c850285a0c1873c57d7158c76dba1e5fa1d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:07e774040e4edd4c7ee9a8981d4aac61d07b85a219cfa0ee1fb163f8bc7ee4bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:aff5f087556cbad783ab98a38f316b93258022e2595673b1687839f68f7f3863
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:d315272da2db5d008899c1f7193d82faf2a589c4b851ac6164d3ae925e957aef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:a76eb769055f2aa6db9a351d5188860d7aac668949fb7bb0c81ec72e6d792a6e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:80266a8c8e71726122086492beebcc1d0a45d3b38be350f0dd53e2de86376134