Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.14.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips, 2.14-debian13-fips, 2.14-fips, 2.14.4-debian-fips, 2.14.4-debian13-fips, 2.14.4-fips

Index digest:

sha256:792dad584f635adc463f2451142494017aa4fc9b0a5ab82c442743e13752ccdd

Manifest digest:

sha256:0aa3fd8a1c5ea5c1f53f97f517096aac8b7e0ac5a89b431a7123f4345ff15d74

Size

17.62 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:a534e51b38365e3d48ded3ef4d685b56a920c02a62052aef5b61e3442c9a8314
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:69aaf912ffb30402d18076197822b1fd03511d944ea20b267cefccde31d5de58
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:b754228b150cf0888aacf9ccec16669771432060c18881be3cfcee8fbe8ba478
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:9047eac2f7d21b9a5b9c81e56d016e016f27f81b212097fbd286cf97be357706
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:7c963229eb72c267e7bd32baf4a5232e2cf95433c6f611fbd07c746e1e1b50a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:de5e14dd235c19e23105f31d69fc47027fc779afea75e2f32125e9e53a113feb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:93cd6130da462b90926002e649e279850b0852a330ffc242429957ebaf7ca1d6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:006c98ba20de0040103fb2b3cb1514c1ff6444ef5ef5065d2c0d3e365ecb395a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:5822d4f74b6d72d389b818d3296838f9d13dde1631273de883ef7fad95619c18
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:b16878271f5ae2d3eb0a8ac7d0e80118997c446d5d21d7d3c0b9afbe37448ba9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:5421d41d5f8d683cf64f9f4a3b9bbf94e1288cba5da6375f38e95313e95efd8b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:6788597c51a8221bac31ac62e76b68f97948a70983adf7d4bf1c9e6a5e813b78
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:9a378deff026d7910d87ab45bd90c168fbdfce431ee1824bcfd414949dfb6887
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:6087104054b4afd23bcad32d7eb51b0d08f5431c02c1ddefb440ed4c69449010
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:2d9367e57825e674f45838e466e53cc2df14b9f771fbd8c7c4badeabd8efd9f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:3835831c694e1eaf2a63b8e7afed75b8bd74f297710f2d0bbfaa7d0691020b99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:2c569159d6f17cc515d3ab677ab78cf3c4e50bfc8b1561615b652437c879bd98