Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.2-debian-fips-dev, 2.15.2-debian13-fips-dev, 2.15.2-fips-dev

Index digest:

sha256:adae2e3db663ccc39a614b13b1bbffe12cc63b4c1659ddb403850118af0f043e

Manifest digest:

sha256:d320c0f18c322210ef34611a798d69739c8ac1ab47dc8db5823ad2ab3bc83919

Size

26.62 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:fbb59040a62635c8a5672204d89e094b509e77fff80aff4c95dfbb2e52570d1d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:59ee321f5030825931fafe45b269622e5d8d329054a9d792d2435e27531538ca
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-portal@sha256:04331e700bb18ec01bf57d813c71f53ae9790c7bf4f98a55d505223c80c3a0f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:d4cda58c32a0eeaef950a7709aeea14a1575f25d3ae1a149de7f4958c3fb7f09
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-portal@sha256:b2dc8fb3701d45793d3b3a9b9287fb8685b4d7babf8627e67ed21599c835175a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:67384b15d4cf59073a1b7a3cde94b00c0406d06357f8805c243e07ed83b402f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:d3cb8e6273efd0a72ef8c96e6c46e4a5ab966fea73296eee4834aad011f74aea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:aa0803606a6469f42917d4fed06f5c6d1a4a131a86330a17c34068283ac9692b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:29245c5411e64a95caa891ef8c738c21d0c56781c5af5baaec2fd27de2daa313
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:83fc5aa6f51dd88a83a41b12390bee9082b87cd64cb6f5f9108c8ff4c7383d29
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:e83a5b1ef04dd20897163bd9e531248a0b14ceee86584f233262f0d4e923f4d3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:131a169bcba865b30e921845f053739761a3b6115f7521adea587c7d3eb8c351
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:f121e8be45709400f30e1105949539a23fc68c498fdb074074b760de18b6a249
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:4a6bdb0a97c11a51bcb217e02913e13e8d1691f0c3f3d5ce48851757089f93e4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:f530122eb6d6a5dc47cc93fdd581091cf994152746aebda0da3d34616215168e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:5c7a4667d31962dc7c16531a7b6ff4104b09f55b487cde927544f72e14b71234
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:f37b06ed7b1b9ba525d4880056ea090ff933bcca881c507477705d0d7377cf84