dhi.io/harbor-portal
2, 2-debian, 2-debian13, 2.15, 2.15-debian, 2.15-debian13, 2.15.2, 2.15.2-debian, 2.15.2-debian13
sha256:ed4b38917861f2009e8d73ad9eb17bcd47a3f194a0f5bd7688141952be705909
Manifest digest:sha256:bcce200e6df239646123383727ad513439c10c634b282ecdb073ab21ac5fe5b5
Size
9.99 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-portal:22. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-portal:2 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-portal@sha256:dccc5c85d5494cd6d3824c26ac32b25f871a43599f6ae91c21c33b1ae9ab76de |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-portal@sha256:cdb452d66c3a71b66f7eb39ec3d5a7884faaaa9e08501dfa9faa82fd729e19c3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-portal@sha256:496e6e5e007c88880bce6d1835dd7f8f4dc2399ca29a76a6ff363b2ef08cef6a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-portal@sha256:62ede2cd3eb582c924d582ad0b6309f33708e010e5e0437e5055723e3c2a7445 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-portal@sha256:e50633d311dc8432d2e2be8e8a9dc82b70eaa8bf328b59f244721330bd9348a8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-portal@sha256:f6cd82e807c7aa208475b91d1babab02a63b388297d1b4165f546f6b095ce30d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-portal@sha256:460d09489e202c39fb3a48927c0507f448c1f79dfaaa2c46bdcc54ec76938afe |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-portal@sha256:f99c2a476f635a66f791db0208ff3f053fe7c2b0622d3cca75d7b47e6ea594a1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-portal@sha256:66441ecb1a77e8a6e930e8c97cdf80677bd38e46204d4561b2bbf319ce84226b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-portal@sha256:60ac2ba100e32abd4462f518eb8ec296f6ab42f9028ee2e572e401c76c661034 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-portal@sha256:7e686f703e098d0effe9a638f7897294a15d08c5b45703cd8a03d2e5cc721ae7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-portal@sha256:3071e6a386df53f5b23e1bce6f556e52a3b563907d4fb9e4f5f5e61111cecbd8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-portal@sha256:99cd97a0a15f98f75d62e7e17512f15e203d81030cbc656305c73051725a62cf |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-portal@sha256:d3a049e2272fbc6b4a8cd03f2279e51110817a035503e79f2901895577a5a360 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-portal@sha256:74874cdc971e12ad738b64841b4c690c056c26905923668d5e4640a25976f1ee |