Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.15.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.15, 2.15-debian, 2.15-debian13, 2.15.2, 2.15.2-debian, 2.15.2-debian13

Index digest:

sha256:4242e4545510f5d4e623edc0bf6e47e5c00bd466360ddd95e568c8bbb43dda00

Manifest digest:

sha256:1b2780ab6e976ecf0efff4845de936dab538612b3fb7901902d9abeb84529c08

Size

62.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:ce863b22cf5c8658dc114f27f7bf07b61e7e324be588617d14a457ffcc52dcc4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:afd7137bec01a887834f58db2595298fbe4cf16f869b613ff7192383d4166577
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:ecd80d987f30a43edaac8f8506086d0e2b90cb0bd95d34b76c546189f60bf85b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:748707f95c3e3c2c4269701226b278537f9ebe0714c6bedd9987132733716a74
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:79ca4c78c59aed428f132b8b3e131fb9fecf5d4c2db82e05011b030a503e4964
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:873afd8944a6d6bdc9679610c708eb90aeb729b7d328d6c3c03e50da77bb3379
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:eb900df9c37855a0c538f705bd731c304e4a2b4438497f6eced27195bb79a7e3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:95a0bef54a9c99b92268bb9da1ec22ae5181edd649bd1ae25196a1ecbe6026c3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:ba66f0f5a6cfab072f901388959d3040f47362b1eb2ae96bb9b44b9c45b744cb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:f5e3d88cb6b85056fe3612ce51db3e39c95f10daeb65f691157eb952f05bbd24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:8562912732c9280e50cde8a5da5cded6e012404f65d76fcd6850802a8e3d4b96
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:7b74eb131e86f545c59653dc7100d3d5864327033d2a14e1f7c2e2baa3eda388
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:0e7421965d3384e62cd0b941c0cc4fbd0064053af789c25bf90e25c551dbb2d1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:7b84c186a91b2a8661082f8e348caa449bd78bb07acf8272cf752362bc3a9b62
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:35ca5f49fdf6c6486775f13bf22fc1eba425d150dcf26c4bb41ffe3b1fd67192