Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.12.x

CIS
linux/amd64
debian 13
Tags:

2.12, 2.12-debian, 2.12-debian13, 2.12.4, 2.12.4-debian, 2.12.4-debian13

Index digest:

sha256:8e951107895c6b674e60c8900ba2815c3a9d8da2b6e4bac1fca3fde64c83e8b5

Manifest digest:

sha256:b2a8288a7b40319c785720b88d908fd742f6fd2d43c5daf546ca2fcc214b8d41

Size

9.71 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.12

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.12 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:01f46621c691d00902f6b6de1fc9625cc76b214b4d3d7d5f851380e1e2eef7d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:675f511c5c5cf1c0d1bcc7646206214dec38b2c930cf83876bb4ee69a2f9f729
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:d7a2f07c1d6b284bb2ae0f78d3d53588f5467fbd18373ca0c4e71b4b04bbbdc1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:5fb0f043a36d61d034f318f00e62e598e71730585b4a884d0fd234797938aaed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:81201854f78fd119d411fecaf6c44d1c9bba946e2a52d8270ef74360ba4cd762
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:bfec0189dfb1b17f5fb3b53c2fed09564ff3b0e08d08afbab2000a93349d94f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:ba35e2ae7addeea8c7495fd2b09dde7c69727b07e46274efde738e7ec9b2698e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:6c0583e14d8b717c174471165020be52d61c044fc44265d56e0dbd91e14cc6a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:830cd9fd0fa6bcb5b7bb5802d59063c98932945e7c8f8af84faa873e9140ed53
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:3341f26f7e0fdd52c0e60857215c5e171cf3349170ca6b3b4141594f19dd39d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:8360a9f7e3c2b249c60b4252975eee57896da79d0bc5c1cd9d64abc42729d7ab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:4c64e56ecc4b4e41aecaa143d3ae5d6f45692a57dcaeabab5aefd9476f62e0b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:d45f1fcc312cfcdb4d9464c72aa4d9c8cf95d3a9f4321046a8f6bbf40ac5f48c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:1a2a3f77af674e9d2ec8ab49a11e1e48169a4c1eab408b8ef2af09970751e939
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:90da749e6da402394e8319056950445a5c148bf44da5447a6c022bcb115368d3