dhi.io/harbor-portal
2.13-debian-dev, 2.13-debian13-dev, 2.13-dev, 2.13.5-debian-dev, 2.13.5-debian13-dev, 2.13.5-dev
sha256:bf8c7c66de001f06a558f23fecd547db66122b455b4293b1417d7f55d49a6ebf
Manifest digest:sha256:c590b4e4c4e15282411fea2a7f98323fd1b002e74d5b83aacbd85a49d8744cd6
Size
25.60 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-portal:2.13-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-portal:2.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-portal@sha256:282388a02f3d3876db2a0117367fd830087b292a1bac0ec52920a557502398c9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-portal@sha256:d0db39c2ddda4752beb41fd22d212f6711f1dd27d3c30d8925915dee72967cc3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-portal@sha256:14d99be6094fc6ba01a437be355ab3a62c34558f45544db126a84c797d53e66a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-portal@sha256:d47d9f66e05a2e2e3260ed8fb52d7242c0489faf1c6908c32ba839a2a3527a8c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-portal@sha256:c29a3c7a01c4cc6e5682d10f3105d96f79094168e6794f7c8ab1724563a0826a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-portal@sha256:d33fa20564330c6b16fde268791f5ffd394ebdeab0459790bee3f3b1e93e0170 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-portal@sha256:d486c5fc7ee18fb69195a99a7d129c4de55ff45a2d0d71d1394cc476a11ad835 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-portal@sha256:72d82ae6a75a31c756e4805d76fe4ced090d9efa7a09bc4c6abe1a41ddf3044a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-portal@sha256:76bd9497ffb9078c4571b4c345f84a69d49cc8999c7e0a4710d973121a0678ca |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-portal@sha256:10cc60177dd71717fa2d7881732e0150816943f57a3b875962dc810eba59cc3b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-portal@sha256:f1276524fc6488f6d39be670899c21f30e452469367ea2b449504150081811a6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-portal@sha256:978d8204d74a0b9fca7423bacf6f593cf1c2c1a375757fdc29f3dc9ebb942ff9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-portal@sha256:383dc86e043ab72b46df6cd3883d54061ac513dc9ebb3522c936457642517c2e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-portal@sha256:50f2d60df2e0604f108d7966a5c65aa63e1b7bc3550f5948a501822665dce0bb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-portal@sha256:af70b9298dd46496cff28b528ebb371e27dc1fb8c00989fde7c8875a05557e6a |