Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.13-debian-dev, 2.13-debian13-dev, 2.13-dev, 2.13.5-debian-dev, 2.13.5-debian13-dev, 2.13.5-dev

Index digest:

sha256:77f5eed51119c4e4245699954c41a8fb94ca2e01788a9ed1e801bf4ad5fbdd2d

Manifest digest:

sha256:ee67097ec588c23bb0114a3ce9b112c98433b63cb96897137b9761ee9beec2a3

Size

36.68 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:ac9a097a9c0ffc0b9f1746ff8d3f4bac71e3955048eeb6ac237c75a17c88fe86
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:b1d86e77361a048fa6388541020ad6ce01e04bb176a3be706f023b7d3afc0e0f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:b196e5486ef7d1731811b87cbf46aadc2dc4ee7c119fed0e4d7c2806f40b1c89
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:f891be5c24914c4a3e6a7da6ff48b6f17159de8c170772b9bf87fffe94189cec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:c6ac4bc69b86af621becbaa02b590cbe5b37ceeffceb0ee02559f1ef410af2ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:5b65fe970bc4292878f0e017e5a365c2c9f11e682c04a5432a37d85b7f7272a6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:ff598eb494d5ced0d0774735831d79bbf75524fddc74d7f6aa696ddffac6af1f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:0ab7187a7bae33d7b866094dab97fc6f573c3ef251681e71ee9f2cc61c941457
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:3b9b6495faa0cd858a7fc6696694436ddf5d5aec7ed771b51743e4f5e3590d15
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:1994d66c87e3ce4e80431d6de121bc239a1802525c851edca431f6d5ed7f0b9e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:ffb8f5bee0b1fa54b5d0be935c30c7fd505ab4a4618ac7db978104ea56189939
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:7e9844e6222a09b8a36a9b07ed2a35dca64d37cbb3e087c81412ae94fb269481
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:d98faf2d391d84747ffd8105495f16bdb1977110043c48bac715392789ac59ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:b0e320156942e514fc54b531f89e136cff7568fa87604ff2477f7e3c0b9e2fd2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:e140e15d59a0a68951d916869a0ea03d73e3a9431d42906716e87c2a8970fece