Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.4-debian-fips-dev, 2.14.4-debian13-fips-dev, 2.14.4-fips-dev

Index digest:

sha256:a2dd91d88b4bd4c414441d6c26f15f7e020834bc3a70c33d98ecce1d89a97781

Manifest digest:

sha256:b79e282018af154a76dc059d6579c172dfe82a06d62f58a06aae4ab48f0f781c

Size

26.39 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:9b570a7d54cdb9a8ff58d13b15c87d06bcb650bae34a19646e360e4b21e2115c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:3b0be4b133d6efb2bd9d68e37cf61218d0e3152e032aa1c775fd41eda583ac45
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-portal@sha256:53e9d92000ce02c0836d433dbb291c8c5be1459fbcf2b88cfd3fb0023021e947
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:2e81136325a7132ffd0009e57efde879b6add395f913ace081d1e3c7aeafd118
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-portal@sha256:b244194bd5692db88aa7897cb3758d346d73bed76d4e6f5e0015d24bc366a662
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:610c481cd26065111abe9025200e2e1382d5875e7d14f89602897b0c2d77c998
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:54c5d21fbee966b9a16b15195d8fdfb368c98625b35737a5bea0f86f8bfb36d2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:d7923561c92ea6f02d5efecaee0cd80c23d67789353305e14243470ab27e6b6f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:a4fdaa0424cc0976f15e04b3f037f2e6a40976047793b59027d0990ff1981215
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:f07253a1e535f874830ee4e778360b78011b752f0f41a7b1f7892aa02f6c586f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:d0bc9be57ed35fa28f9f76ea12032fdc8d944192568b5aee9c538bf45301301b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:1919509e99c03a351f81d669086d3e701c3e2bbfe53b102264e5591a35cda70e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:5b906d752f226a0d7961c9b8533825dc11624f5982657243e5f6d43d001a387a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:46aa8f67dfd32716e81121d903e6187cbc3a15db542f447fdd8e10b65fa91efb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:2db79e8f7ca24a90f12ebc1cea369a1f77c2f8faf5b13463fb939c61d3c6d02c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:f6eebff25be673db584c47f104b2e4e17393f4b82293290275f63ef5c0389c07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:fa2e314efed05edf06f4d233fa66ae35168c92598912dc24c2e832e201b60785