Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.13.x

CIS
linux/amd64
debian 13
Tags:

2.13, 2.13-debian, 2.13-debian13, 2.13.5, 2.13.5-debian, 2.13.5-debian13

Index digest:

sha256:9db630a1798db6c2f5f5b8b74b91e8ffde2b3781888c282b172f24a622e4014e

Manifest digest:

sha256:e16aad95b1243d6bcd1433f3113f1250aa20a7bb39cba16f14e1cf009d8b3667

Size

7.85 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:93e87a0f65fb90a25dba52d8812046142655c3b3b4800431a814ec15764e4151
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:a0ec06d69a836763a2ddf68e41b16cdcccae193928aa7f87304888f312269d22
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:2e4ad94176ceeb66d62311c3d97d75f2747b1e09c8901ba9028db916c39ecd96
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:fc22f79235f63917dc2e39181c9a6899f97e5680fa05bceb5c4e6c1669951ced
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:d6a561b4d6493d59d9006fce7c5d577d1635a4dd4702714208f3e427e41bbd65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:3425451b4d6b0935ab87240bdbd216bb9266458d1bf21ecdb9104efd69b070c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:3bbd4a1847f1eacd9443bfdb70a5457decc183d5752333ca9f27cbce1cbe7ae2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:f019133f4d5953b69f3cacdbf0f8f651b8917188b3c75ea531fa1d45dbb18aff
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:17a37a60b39d52c952bfe16eb1a8907b3e0dc50acdc0d00da8c51412b03553a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:570a6df1b28c8b24d1a6f20e1f0c94307003b738d63074d290cc108cfe1cb78f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:7c300e7302373ff794c790625eb7c279aa16e634d141c7c35a9586c5be58702e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:ee3fca539fb82d2004fc3b180de050f4f5f51b6ebe2702519de5e18e43206da8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:deeb47cc64dc7a6f364c71a33d3d9830a67779c3620296c3b1fa211e87f1d01b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:dc19a151d1eb9e5ade3ecfbdc782433072f0eff1d1dbc6a1e445abbaa7ead112
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:b9b03a2f09f06e0d7415176444235d72b1ae1ffb0c8eb4b539689fc6638774c1