Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.13-debian-dev, 2.13-debian13-dev, 2.13-dev, 2.13.6-debian-dev, 2.13.6-debian13-dev, 2.13.6-dev

Index digest:

sha256:d18d2091edb76993169a133fca2e87820a24eef30e7888f1f0554301f44b47f6

Manifest digest:

sha256:21e3a9dbc25a106340c8a2b170f8f8d10208880965899c88918efeeff7ec69cf

Size

25.61 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:2d130340fb822a878df61511cb6c1777ddd7ee17027c7961b38108560237a810
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:383790301be41d23e06a124dc869c5439d4bb97430bf4bb5c5b9a771861ef76f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:995f5ce9f2bc212acb3211113ca64143412faa97adedd5ce859a745069272b4a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:b04dcd03e04df51634d4014543371af92898ad90e27c66c6b0c64760b23ea220
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:4b20093f4324f58369b6d08ab7ccb58185180c1e47c8a31adcab0c4e7e3757fe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:55df8563696f1ffa0de5896dd3bcf69ca7b328a1ecace0ee1e32e0257457cf43
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:9b53faf7d7a030b29ccbca1567d918b332ad5f84fd4dff034c10ca94f38dc14b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:f5a8b15afc844962ccefbfe321d222e8ce4883fa7d2ec62ffd753ec9a1e66434
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:22c99e9b567b1fb058e47f9ec0b5624d7b7d565ffb7f3c3222c4157bfd5e0b55
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:7df2ab9ffebefe79abc97e66d7630896c9914e14e710fc989f66a8a7c6dc3e24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:b8f59b2a31ea51ffba31996b7cd134888a06edea05089ba0b978f8d79331286c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:3ed69532d5ae925cee56541fb9d7f9420a2f2fdef2915d848f18af5136e45958
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:07e879804885da5552397704f64642daf14212650979ac998bb532fa93b9f844
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:5dfec6bb8e70ec7c4c53de31a5b0be7c3dc28344363b5d3b9814fd5e12b9ce89
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:631fff5473f26832b31bdc48b558afaea93ab0948b2168570b4608597835a608