dhi.io/harbor-registry
2.13, 2.13-debian, 2.13-debian13, 2.13.5, 2.13.5-debian, 2.13.5-debian13
sha256:9db630a1798db6c2f5f5b8b74b91e8ffde2b3781888c282b172f24a622e4014e
Manifest digest:sha256:e16aad95b1243d6bcd1433f3113f1250aa20a7bb39cba16f14e1cf009d8b3667
Size
7.85 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registry:2.132. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registry:2.13 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registry@sha256:93e87a0f65fb90a25dba52d8812046142655c3b3b4800431a814ec15764e4151 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registry@sha256:a0ec06d69a836763a2ddf68e41b16cdcccae193928aa7f87304888f312269d22 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registry@sha256:2e4ad94176ceeb66d62311c3d97d75f2747b1e09c8901ba9028db916c39ecd96 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registry@sha256:fc22f79235f63917dc2e39181c9a6899f97e5680fa05bceb5c4e6c1669951ced |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registry@sha256:d6a561b4d6493d59d9006fce7c5d577d1635a4dd4702714208f3e427e41bbd65 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registry@sha256:3425451b4d6b0935ab87240bdbd216bb9266458d1bf21ecdb9104efd69b070c5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registry@sha256:3bbd4a1847f1eacd9443bfdb70a5457decc183d5752333ca9f27cbce1cbe7ae2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registry@sha256:f019133f4d5953b69f3cacdbf0f8f651b8917188b3c75ea531fa1d45dbb18aff |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registry@sha256:17a37a60b39d52c952bfe16eb1a8907b3e0dc50acdc0d00da8c51412b03553a9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registry@sha256:570a6df1b28c8b24d1a6f20e1f0c94307003b738d63074d290cc108cfe1cb78f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registry@sha256:7c300e7302373ff794c790625eb7c279aa16e634d141c7c35a9586c5be58702e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registry@sha256:ee3fca539fb82d2004fc3b180de050f4f5f51b6ebe2702519de5e18e43206da8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registry@sha256:deeb47cc64dc7a6f364c71a33d3d9830a67779c3620296c3b1fa211e87f1d01b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registry@sha256:dc19a151d1eb9e5ade3ecfbdc782433072f0eff1d1dbc6a1e445abbaa7ead112 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registry@sha256:b9b03a2f09f06e0d7415176444235d72b1ae1ffb0c8eb4b539689fc6638774c1 |