Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.6-debian-fips-dev, 2.13.6-debian13-fips-dev, 2.13.6-fips-dev

Index digest:

sha256:b197e0d1869d2d58951f5a35ba296b962e68355e04d9612b432978167d5c12c6

Manifest digest:

sha256:c1020e302557f5ca0765ebe3bbec5ae9e14561b53051a9974f9d16b4a421fcb4

Size

41.15 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:ea3121444df1ddd68f303f79936524bf62cd444c00706f801680e052f6bd3ee8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:54bd08577a9081d5b3774616e32df9df620c2a0da7e868789ada834d98178696
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:2693119f88cd59fa74b125c226a1e57cdc7c2dd444b39b191843edc731efb15c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:48ff40b0174ba767fe05719d4664cf030e867b39486ba22b11f70c3803d10f8f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:341e5eb06f4d61cf175d183dc94e18c07b53d27439f2c0ef9aa6614aab235bde
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:8a1d5cb6b55a892afc8346f086354b41eac84d86c8692e43e7fab519af67b72b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:62ce4d7265e962cbe99e55e05b6517290ec0932ca9eb17926488956c9c5cab39
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:732c68d88c16b21c4f05cbbf947e301d448858b110e63d8a8c2a2fe3569ef202
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:018dbd21433ef92aa1fc2f3d08b5c94fd9102b71719b084de0d578ce06c298d9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:7044e7556b9b908905d66a25c1ecd6eaba7d92bfe69a201a6cc171d683978f7b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:faaf08c1183bba537805f5efda299aea2f316a697a7ea669d5765f3796f8d0fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:66dc9c2a897eaccbf011238d46f28ae4e7ffee45a9a43e675542855724d15e2c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:ec6615470d7321eb11097e8c1d0c131754f5673f20e66379e160973041558e2f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:184410fca57945011a26824ec736944965862a1cfaf8f4bdaa0e4e73aefa06be
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:6deb0972014f7dbf5bde98f3753ad6e8a7e03125f6f056cf3b607b9a91297a23
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:1951fe61668c2d68dc234cb337d8d066bc7b20f6f1da13f90b128d8dcbb26848
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:7283e7300fea69391bfe93a0c44f2d736ebc5597a69fc78b611d153170530a84