Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.13.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips, 2.13-debian13-fips, 2.13-fips, 2.13.5-debian-fips, 2.13.5-debian13-fips, 2.13.5-fips

Index digest:

sha256:f37c7efce244ed61bb655a9c6682f6ca16732386773d16d911d0998ab1d31b9c

Manifest digest:

sha256:f549927fed1be7ce4cf795aad10a8d0d8a7fcc4424a4bf925393fe8b0a0d142c

Size

16.03 MB

Last pushed

48 minutes ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.13-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:5bea362e3ae45a1dbc2e1d8f1682f511aca4d6896923ed37edf3671f4fdfd9c8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:894dd8933e4dfeb0bf25eaf84833e8e9b599b1c894dda52c5cb48049de4e7dd2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:e7b679e1b3bf762f8b1c8a8de7d2b6bc8518e6f53f69527378aad4b09ac0da04
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:37ab14a8edef6f4b496c251cab8fc843370cd495a4ac60426e7df81c2256652e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:78746274a441fdf0f6f70e6b00ebc9e53ccc3544d22dea23177f2bfe1742fe9d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:d352163f0ba71bb2e51876dc2cfa641980bd4d8c5222a35c1c8d0ec7bbcb4c9e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:5d9b62711fe3e054c2c89b006f941dcb82d3e090458ec97d9e66b421d7e636b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:3690ba2fd50bc517ec89ee780948cc9c8c3c7459f31af8c251731340eab7d45c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:b43f443465c1fcf295453b1fa2480f5fff4d4ecc09700fe130d6e299f730174e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:39d31d33a96c9b3ed9fb81a1c8fd2657b417d45f30081721684e51ebee3a5ae1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:b81ac01bb2d65e19363ad97148f2effa34ad739ce13b7cba3fb2116c9dc5e604
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:649e99cd05472963da22231a0503ac6e4853f21697ab888c417c7bce2731a8df
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:8c6eac01e57a887b4b85dec63e294bc592ff19c2b1b90a5c1bc849fb3e70712a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:b6dc176c638e0d52e26f90ccbf752c416287a39968fdc1ce72f5a5d6c37a9832
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:72150634e2eaa9cce26df8f7950c8697bda4939a216011eb3260c86b1c0850af
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:076e975437fbffaf80e592cd6d90b9d2e607e312f2ce40831d67dd795042f508
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:d598313e4d1a008829e8529bb7884616fedcc8446b6d6668d222498b0463f953