Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.2-debian-fips-dev, 2.15.2-debian13-fips-dev, 2.15.2-fips-dev

Index digest:

sha256:66952ab7b5191045f3cc31a312d9f4de9a434d2b9e4631ebe77b846ccccd2489

Manifest digest:

sha256:1971a0b92f4e088afc75780028fa4339abb3774f522239236a58e28ac6081d32

Size

107.51 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:f9caf9a44eab7af445cac784755a3fb859171febc970824233dff163fc23628f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:2adf78c1e176b68a6604fd3345e102290186564a554818907e24eaa924f356e2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-db@sha256:203f1dcfe6dfd3999cab057458291a11a65e3949f1cf46b0b0947c1cf6b3e8b9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:3dd524158ee953274548a52a11ffc2cd3d3a13a8f9cf9e9288111cda0fd5da83
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-db@sha256:6af1f65328152a8276bc951eae50abc406a36160605ac3775ca35430395b4df5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:b41e310cf1d80be097218732696fc4f81c3094d7171690c2784f724f9ef549ce
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:370c36f6592d9ef75a7d759e46d784206d8dfb1bbdb4a87cc88c8446ba69edfb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:18fec42ccd001af736b9a58c08ac78de3fde2a6324a9b7f0e768460287362864
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:f8bf8815cd68f3ac48ee9102abdfb87824ad393eace437a935596fb8a9fb7c53
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:ea88fe34f1f9269bb492e4ce56898466a1bf41780710dbe63acfc465dd9a0c91
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:8cb1065abd39cd10a821c3d527c88d8101dd78510e533dc85f2599165376e06b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:7ab1feb48684deb8deb1ce5d040ac183984966158eee9fa60949212daf852320
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:84e60723e504ce301990f60199f582eb18173ec90605774e350cbd90be1f1be3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:090240a671dd0d775e7fa0b52e45c65da5dad21dfb3c7429e73ac369dd650672
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:eea4368948a3803414f3844edeacd12b76d2d293c9c42aa03e8e37423b078e9d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:98c91880e068dd3d1af0a3d348f87f395cc00627e7beefe3095e01787607c8b1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:784f4ee412ef1f853b61da20de62b97b07fce79e8c8144b7f0f9eef513a2311b