dhi.io/harbor-exporter
2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.4-debian-fips-dev, 2.14.4-debian13-fips-dev, 2.14.4-fips-dev
sha256:113d83bb10f58b51f2a68fbb6e845890baceff791c7dba36b59e431ec1f7f0be
Manifest digest:sha256:70bfab77ec99aa6d10403b2ced4828cf5901ec2dea099f47ed5d1ad350c26a64
Size
41.15 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-exporter:2.14-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-exporter:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-exporter@sha256:443e75d7747b5e1444d386c8c9b48f8b56861ca18d6067af682d7d78a82d888e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-exporter@sha256:d01177ae9223c5949b82404809cad2e845e0b6306857427f73ed69c628564f84 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-exporter@sha256:fa508b9901e964eee4abf1fa5d56f6d58e658a6a882f5e82d29a65cc7b0f449d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-exporter@sha256:0989dd2dc8cf4b053cfe71aad24d58c0d66839c5f242b0c6145ac83e14174afc |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-exporter@sha256:a26a92c0bfec53b5bcb1b7353859e44cad112b96e0c213040e76cf2278c10872 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-exporter@sha256:8c260e3e13ff6446fb08685df39bf9f403eda5293d5dd439f129dd08269a29ea |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-exporter@sha256:bbe851430c39c84371a7e92264c899ee4a0cc99610d787d980a55d4794625673 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-exporter@sha256:d85a0719a198944ed04a7fbfc454c44c7dc7e1354afcf1ab47b7ba3246a58168 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-exporter@sha256:b9e93713a66930e14d0af74b3250d87015fc8bc5c8503c64c504ad3780e36ee0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-exporter@sha256:5fb00cae8745afd0c79eb65003bd06cdab91ea7b15aedb6b17ae2f3bcd353125 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-exporter@sha256:010f5b0cffa366bcc3a486b02973e7353e3afd058d93f5cee6d02b26ff6e21e5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-exporter@sha256:adbcdd18529cc1928a5536739d8af079f9a56ec65c1d935829b1f09061ac67e9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-exporter@sha256:d8be1fc78e80b7af5c9c06408074791db9ed32708ef8ec7d3a066873f75b66c2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-exporter@sha256:5ffc4afa15194bddc65abe80e11696bec828069caf5287dcbf1f9ae5916bd3ac |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-exporter@sha256:ddbe9a79960fbc3b87055101625c23b1badd210c53e5ee7370b93890e0b650c2 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-exporter@sha256:12791b57e4c34d98ded372d21caee96a94d75d2a101a7cc975ef3ca520c6b1b5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-exporter@sha256:5239cbdd3d51d38e5b6585519409fbbdf4a3e7b44707e57b453fe4d5bb709056 |