Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.5-debian-fips-dev, 2.14.5-debian13-fips-dev, 2.14.5-fips-dev

Index digest:

sha256:7ba1c974ff4359256daa5a50a85e37ce16c06fbcfaa61abd889d7d617052349c

Manifest digest:

sha256:37f19a7c9f32fbdb487141621e459ff621c5448eeabab9c47de52a681ef4cd0f

Size

26.40 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:007fe45332147fad6bb810961e6ca64753b97e751b807be989acb2d9f6e1f366
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:3bcb2744dd2d6f11eed755b55ead8f571529e12df6c8fafafa00e30eab9c3103
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-portal@sha256:dff320f654ce913146281a0c2978e5ae537fe4db44c5b8e3220ae54f350c9ef4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:7179f820a1b89e55356b645fbb4e9bb166625d25a646fc047b8a0e190ed4390d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-portal@sha256:b122bde96579956848d49520cbd3adc23b605aefbeece13ae88476e3b89959b0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:3ef6a436a7a6f6e9bdf4b59793ba6a41a4f49067337435006e795de4f2bf9b62
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:6fec777347a9bc58691fcb5a71d476015f228e7c113326b1b5ca3348111f667e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:5c6c7ef638a01e3df99f693a7f1b1029595b59b8058c602ce4f1b526ed9c231e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:0aee94856ff2bbbec8d6aef535182cf78905ed925b9c64e25c1f665dfa51b279
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:78a16e839582142975d3cde10de11343fa1778f60078066f34390ec93020bbcf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:72301844cb214b15c50037f837ebba478deea08cc399255217e82485bc444c01
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:426a03771c9e467a7f99ec7e94053ba7ba3ea048d932da94e8916e47a0586ce5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:02da94f3b6eac0c768c3e0b83de7041a57ee3e3f54156f4e01abe294f3054012
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:6895348f3f750402a864466e426c607c27f54d0a6e8e3b98ba864ca6fea7c127
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:578f3eaac2b335c2c31ef0b22d6a2c1f36135b7fcc208c83587261ad7f139408
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:b362c8bcb2566a315edd251b7afef749c15e1206c661d51226f31aecbf20fc35
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:deab8cfbc6846bc68dbc30dec347900680cbe26ce014d5e5fa9edc94367ebf37