dhi.io/harbor-db
2, 2-debian, 2-debian13, 2.15, 2.15-debian, 2.15-debian13, 2.15.3, 2.15.3-debian, 2.15.3-debian13
sha256:3929df59378d35647e16379bbf6a8e84ab43624c50eccfcb7990268565fab223
Manifest digest:sha256:27e0cb458d69b836eae0aa69f8ddb6eac28e35ff6a8d7fa84792e63e5ba5e5c7
Size
95.75 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-db:22. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-db:2 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-db@sha256:d56e9261dd9b6b624fa3194bf3f9141d3c75960230431f242927429c448830b3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-db@sha256:6ff78018575727490a0f589449c0641a252d9096839a45995bb26a006c2411d6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-db@sha256:ea9dd357288155a7372eda1385e1127efc14431a1d422be99dec1432a41b986e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-db@sha256:770284430f0e7de5ab433231dc7171567e359aa967d93acf271a0a890e278fe3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-db@sha256:408529ef72dc78f43dcccfe940931b40a9eaac040324ac82fa5c1ddc8d636800 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-db@sha256:723bbb7e9ec9cd8a4c3560aee11c0e8b5c0d351f465f6cfa865fbfbe86a470b9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-db@sha256:6eccc05a6fabb01e3865b328aa09c3066249726654ed7c60b1fac64f9a4d89f1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-db@sha256:b79fc1928902a6a896fbb6c372d091b31a2654189972d495eb43c05d70800576 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-db@sha256:79dc9e4414c51d930f282f11c97c2b1f092bde45073ba5444a4ed1df4d6d49f1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-db@sha256:30ae5200c54c27030d4c94e1e81946ca55aa3d796b41c96d57c1e709db523a80 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-db@sha256:d07698435a277963873cdeb7be06706918f69ae2381c715641d9083895a1edfd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-db@sha256:0554d3899b557f80b79cae746c609c101a0f1aead62c21774f7cab748d45301f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-db@sha256:597c4e919e17902d0838b0d964f50d6cfc4c5713853d973cac32c03a948d9f5f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-db@sha256:e88b9ebaacaf541a284c2322d4f83ba9a7a870f0b2dc63088cc0dfcf09488031 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-db@sha256:e7a5e23c71a68832995c0521b4ad1e543d6bbb6f36cfb5a24ec9d3fd3b73dfb0 |