Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.5-debian-fips-dev, 2.14.5-debian13-fips-dev, 2.14.5-fips-dev

Index digest:

sha256:a83003f04cc764861cdd522f659c22ad2ddf61f08392ff0af050b919e2287923

Manifest digest:

sha256:6400eddd981aa9dfe149e66eebda9f38b4a4b21679eec93a9e17700f3d6eb3bc

Size

41.18 MB

Last pushed

16 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:fc10fa49d75ec00b0dfcf430a0420504a59d91b31517d62cd7cebad6025ca2ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:f6778d18e18dc99d83bd56e5c12311771906f8ecf7ca9a50bd4b96d5735b7659
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:90a27dd7918da48a1d4c57690ea9ab8ae0050a308a3a82231d42ceab28240a2b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:00a81709f793054a365c8beac49ed8739983d4bc13b902ce850fce9cda8838cc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:24ebaf07de30df36898f9baf0d2f4f3d511019a5fe9902d89d9c3ce97b3a33d2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:57a5bded701aa80e03e0c68c253effb73f0429def6cb42488b9b7ac8b6a1d040
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:1c77294f44019555ce05e14e7bb0b030641d9aa36617e793b9d105c850d73f27
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:1ff66f6b9bd6b3df18ce5e6defa59792c8bee2ee35f8884374dc5636acd5f612
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:9a8aae71e066bcfabaf6df52ca82f6d19ccc49d90e9b081ee654d9aca19c1ea4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:20f2d54d29ce7ef55caa8a5cd43e21940ec11f4402cabcb0b5834ab05da87bb9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:23d3dfa0b6f2b0bbfe000d4f66083f94e6627cfbc1c1fd24110a99319c55c273
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:8da387fb05c68d0f6fa4ebb190ca491a8a799caa0864d7b3ee8bac0cf3d494a5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:5b9c9cee66b7871585936cd6fb579eeab21fd9ef7ba29020b4fb489f7c58373e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:00d2c9c53ac6ef319aa60851ba3382ddc84f11032a387d83e836afee6b17ca85
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:f1e5eebb9b5da1eceb2bb34316bb27aac2ad3303a12dfbc8bd58c0b577f9b9f8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:07ee04b17e09e931ccaf463ff2f07b68d57b626f3a40a8177500b03fa64df60d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:00f619edc11731aafec74e1d10366990907d491fffbf90d7cd344afab7b6a058