Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.5-debian-fips-dev, 2.14.5-debian13-fips-dev, 2.14.5-fips-dev

Index digest:

sha256:be15cd8f1295ae3a0eb40e05c529334579b46198ceb07dc2a6541620ab803941

Manifest digest:

sha256:70224992d6c6ba6129c9edb23487f1b5262bf7f25dc4feb74409972d021110a5

Size

41.18 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:a6c78d6f35ac1ae13f51001db04639788ab1c968e50df886f868f078845f40a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:242ccf613a2795b482463eef05ef0eea9beef46db1dcae0b0c6ae80a45574fce
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:65c6a11f6ec3c4bf5fb891e1717429b1762e22fb2a307eda31e39d6b9a617649
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:8e4d9eb828d9da0bd08161934ab5b2810df5abf122128080cf49f56f6a3d8885
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:5fd1a500351c5faded325884459e8a79dc2fc97d68d7acc9c823a5e0ce909922
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:2bae08351415d1e145f2f3ef2eaa24d7cb6705eb38319a45d0ce79a1a5e71834
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:9b75a010d1c39c841660b6a123f087a2f7d2087ac7e40b207fec37790b3066cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:3e18514ba802fbed35a2a1b10a12c1147fc27c8f9c6eac8826618ab23af943ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:d09ec9f5a1cdabd1e69d1ac85e0f07ce819738cb07145f9bd3f9f2de110a4fbe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:67b7b41559bf40e90d8b47719d12370e80e5b9a1a13bda5f9d691b9d21ec8b28
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:e6002219df10cf73976b48364d2ed8ea3ced35d2304af888cf20fc96f5d8b1a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:cdae5361424f132bfc040c4598585ef29431d32d11a4a4bc6777972d64c569af
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:92a6acce8b4c215ae1caa480222ff9eb95cabf170ead05a8f305c74baba662f5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:866030167777fb04cc2e1153009ce1004c7d7d343e4696d5b23e90d487b33b04
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:8aeb328ab5c37179e2c30a6f2bf3e14479bbc7cdda35330bdb6be4c99f6738fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:7e710dfa0c815a3e4cb51f3582bf6d56b1bcf5fe83bbfe46dce255fe21a1077f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:9d908119be47b8923b0f3303e22ec7c7856843cba3967e97394c527f3dcd4289