Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.12.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.12-debian-fips, 2.12-debian13-fips, 2.12-fips, 2.12.4-debian-fips, 2.12.4-debian13-fips, 2.12.4-fips

Index digest:

sha256:f29fa7fd6abc92e88f4dcb9bfe557ab99225c99dea06623e8dc9f9730e3b0669

Manifest digest:

sha256:58ee363f7cb0cb9de19d1a8df69abf84ec27d687a6eb6117f13d3ddc3c0a6414

Size

11.86 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.12-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.12-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:bb3b8c822a867b1cb74a594f3d0d231189e24149c8189bb6ab7693e1fcc307a8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:ab93591945a51977802ff0e4b1e9e2baea47927c852734df33d448b7f29f0946
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-portal@sha256:edb24483fe5867bef424ca213abe9c5b88ea6b19c7e090ae092830f69beadfc2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:edabe7b84ce0258460c577dff106286e0946f6aa7e7eb19544f9a3cd594683d0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-portal@sha256:f3734b9c4533843f1920216e5ca37e7c15b803f7dc2701275005726a86d5af6a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:fb69b3dd9ebef6500bee469e6274c7a13c9f99741cd6d535bf11df2c36a4ed89
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:1d0c7177825a0acd30adca96a06d3cb228aad02e039e43d12f7ea9a00867cc92
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:9095b70dd5e4b90ebdf194cfbdf15e71ec497feeadc1559112e9e38860ba4d6e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:35ca5d43788fe0032f5d7b4322c50c679326cedb63ce0e6d33f34e1b3f55d9a8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:c3cfba0097580942abf900b694ce311aad0134b1bd8b8f0eab0293a7e3cfb0dc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:f72c07bde628f4cb3f4933ab591b4567b8e933d44db1eb7b01e0744910c265f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:33e64d60f4807314bb080cdf5b7b039ea0a68e620f572a7180644136515d80d3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:0d34a4f3f9f218ddf6ec3e9416d76489cadc41f5a35faa7ed890430214d3da00
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:3de39e06e90ee93a0512534769c37b1abb9cb42931dd8839110c2b89df79f149
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:864b2ce88375e6d4037b972e9ddf94a7bdbf2fe49e28bc8b05be765a50c77f0f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:edc6145b65f328bb44b754da940a5f910a0fb0ee5b6f3ae4a2a4229e2d4d49f5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:0aee5bbde15a0d53088663298312f576b238ba7f3dea27e15d515361bbefc2db