Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.13.x

CIS
linux/amd64
debian 13
Tags:

2.13, 2.13-debian, 2.13-debian13, 2.13.5, 2.13.5-debian, 2.13.5-debian13

Index digest:

sha256:6dcc65981bd05aea51943452fa06c90f5c9c78e4bacbf9149c491000bb232cd6

Manifest digest:

sha256:873a09d9a0346e251df8e546538347d5d92fd778adc19be7a9a56245bbe041b4

Size

9.73 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:7009f1a8959c5105378375af30aa0e3b8190de906b0f0ce2a1ebc266d255341f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:69cca727bdb77c8f235c1c8318a5f4f372e5e83a88d337929423d565b4359580
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:f67fdd1660010b3ce9d412d1882e403477f5f32743f0d2c101c8114f75559aa4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:d7a28c0acc67ac3268c7448c5be52133010650642891a64885cde3f25f4dd55d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:59f6ac13b6337f74095a11d3edfdf7d4e52c59ab1c0ee1083f3c90d997fb2ffb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:e76b5c1379b00a7cda2b3cebd89927ef4789b589f45809244b2475b2d7c6c7d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:414ef5c2082693c94ab982c34f905d6822827b0e6b5e48d7197a911eda6e3986
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:1a54a52eaab162084054eee415180ed0d65a16726ce94ceca0b22d7b1b51896d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:1955b398474eb9c3dc7929571fb42dc80404ff6e95239e18fa9483f3e58b09dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:e77a603acde35dbd42411dd79139a198e74aefbc87d8ee870afc477f8c48f0a1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:d50d0392e300dae77f230f120b8682373db709fffa00ad45ab8d54393e1365d4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:040fa09b095580e73fe68261ed295756eeb0b5b5b5ac1c60b50b372291c26856
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:1d57c7378bba4a0249cae7be364901ab9fe67261d38b268cd1c58ebb22fbbda4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:e6a449921e3254ef39f4d1a34c23cc51e162d62045d8d803fd4ae24908390014
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:30a23cab8a9fcd299d002fadf60474212f249db1a8af4fc0b97a75433d8267d3