Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev

Index digest:

sha256:d97c710c648ce71ccca63a6c933f04947e145807596082f75fd37179cd96ee94

Manifest digest:

sha256:2a51eef0c214f344075ee4e2fc51981110bf5ed30e37746b52e1dedbba6da64c

Size

37.46 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:69aa63287aae87a849f695fc57d6a4eb134a2a1a9dff9acb9403ed552ca27d1a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:24f6eaa0a2186ff04e6ad4e3ffb3df3bdda0a19d3d32b4c60e5b5e89ac2c6fd2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:b2e8011791a495b060702861ee7f00a6344e1d2e512a32bcc78e9ccc946f1c90
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:37e5115c7f969ec3dafa01619230c4ca993af0f4fb07bf26b887d521858a9131
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:38b674df8302d6243497f4aedf5ccedea54afb2b5c82669c188a3463ee1baa09
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:2e1f1dad1521ab4921b155d9fa9ab07c4ca8ce3df9b46b2279faf1c30cfcbc17
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:300e07e485050cebb8a41cbea1e099ad7d7581483beecb751f4dc9be05930225
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:fb60c4c939afdc3c2f72510a9f284654deec8ea5436d1535401a65b05a49eac3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:e3499a26a14d614664c030c3cbe414f6b0f636f29ececd9eb80220207b838171
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:bb81a41c277db9856e1103a5f68dc73d55348e657905bdcd510b72c364a87374
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:054593b88548a3708d97a5b2afa76fbae6de81b8942afe68e66a75200a25fe13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:73d1e3aa91a71628c52553fafcc0bd9ec29fa88d3fc055efac58e5c60c0d0827
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:8f1bd18cbf907914332e3053b8fb307a01fa74f0285b6ea7d4225d5eee934c37
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:39ce0877274c6dec577aa8872e9fe6581a44c50c3dae34b746d60186945c26d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:1c8113852fdd8ac8e46f792b1016b34d1c3ecb68c510a5d9d46abf37fa72453a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:226df983f5c9c37027adede3125b85222abd643d20603f70c3241255908b3e36
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:012a7f2f1312420a0e729042dfd371c9d1df5e64271f9dac7010aa7085aa7f66