Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.5-debian-dev, 2.14.5-debian13-dev, 2.14.5-dev

Index digest:

sha256:1d96589b543d67275bd7ec7caedd4284ae902193815a9c02af3009586b4af051

Manifest digest:

sha256:66531d47408f2cbc1af8af098821d900c552ab74e2dfc4183c36d508438869bf

Size

25.64 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:f2a467a981a326cbd1bd5fad6f322d631e22cf0e460b2718d024c3a597e8d614
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:cfaf05c8c6def361ebc931a1d860d05f1be39235553c42d33c3f07d48fcfbc73
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:0625d88dc6a0de4f44109896c9fa7604d00874dd2864f565451324004889979f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:5bc6bdc6118d5246b18880feb7555cfa60624cba4c8d7dcb1bcac59e4f2fbc98
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:0b662eea5160a1bd5f2e30a806cd3f35b1e7fb3958353d4a4ca6b66fc39b34be
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:0046dbe6d09729392ea764054552b185db16d0a6aa185e7b2adad625ab14f7de
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:482d0f56a517a227f955ab73e054b064e944bf04a2a0fc2415f4565a7b3ad363
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:38dce2d089c8a373130b34ceb8d44ed26c28765075d37dd4725013afd0c700dc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:6b55b525e946d966bdc8f3c7a5ff646176ee0f5e513ce97f8e9c525ab50025de
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:91ef5fc182f8588111ffc1d71795631ff3600953ebd0991d498a0c962cf25de3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:3327c1bd374444ef3a2b4f6a474995b7175eca948078285baedaa94293c44c2f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:e2be37bf3151cf78607fdc989a7c4f0aeac60344b112af6ac4c089ee73e53c65
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:1df4e3d024b00f06b41e9cdff7863f69ca3f24382041304fc8dc7397a59e40ab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:bbce5939a5880b0d85e452ee0d163c031f74287bdd9b6687d32086e5678b4663
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:b037ca30cef9cf1d173df2979062619b766e65b58b647af22771eff758588a3b