Sign inSign up
Harbor Job Service

dhi.io/harbor-jobservice

Harbor Job Service 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.13-debian-dev, 2.13-debian13-dev, 2.13-dev, 2.13.6-debian-dev, 2.13.6-debian13-dev, 2.13.6-dev

Index digest:

sha256:2d86a1a7dec60f524126478fbc9d707004b35f99cda6c1136873f25c47343ab5

Manifest digest:

sha256:75a411644c2c26f8c95bc31467eddaf56e195d1bc6745d7b0a8676e0fbbd3d9f

Size

46.63 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-jobservice:2.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-jobservice:2.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-jobservice@sha256:07e0c71eb111787c5f3fb75f5fab99d5524ffe8ae0964ed726dce23d9a395c07
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-jobservice@sha256:4e030158080bdf07b4c744ccb9a4e085be160e5a452ab54a65a8082b156481c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-jobservice@sha256:8e425661a2f9a8153918a93eda4d4a9360bc30df216cce06acd6cce0d3498fdc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-jobservice@sha256:b0f07dbf7296592e43bca6680b44dba2c356d63388d4ef934f9b8b5fdbbe89a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-jobservice@sha256:4616012673dcc6a880e92dd2effa7b3d060c40c52b375d4558c5c6c2f4c9e5a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-jobservice@sha256:445124e7815253b3f0bac0f35fa75db4744a3aaf69275b5f90bb15437e73c1be
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-jobservice@sha256:8912c66c3344a237fefd964f9ec89bece40a8f1834c3af326ab442fe3727cae8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-jobservice@sha256:42af968c766a79f8a3f6a4d1cf52020fba522c0988efe9be19dd78bf3943227d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-jobservice@sha256:4965aba38dd2cf07e173d24b8b2eca9bfd4a9067628402a9f76c2964ba30a03d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-jobservice@sha256:111dc84c891b3fb12395af5ddca91903c3e8052b5952f614f47bb28acd128a57
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-jobservice@sha256:4d982fe096dcab4dc00d2fe26d0cf0b96e663fb9e70bafa68a52e94961208d7e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-jobservice@sha256:62b39cf42745d7456680a9847e9c3e510c225278a70c5c7467bc42e0df62e63e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-jobservice@sha256:8b260a2fe97763c507a7b81c6129ca2ccaa792534ebc7f023ced35d8f5167250
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-jobservice@sha256:ed46cfc7c60a51b77b4782cfed0bdc71792cb0df989431398730b45df3d9b167
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-jobservice@sha256:9f2bbd47c754160936dc62be6dbab79dfa7fbc4e46ce2ad71f0dd5f24d2720f9