dhi.io/harbor-registry
2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.4-debian-fips-dev, 2.14.4-debian13-fips-dev, 2.14.4-fips-dev
sha256:bae8df4cc2ca75af25f8ac175a34468ce96a1916ce454124cd95f2dd081d078a
Manifest digest:sha256:69af902888758c9aa880e539a4cedb58075fd7ef9687058ea4a597e764eb1f80
Size
37.45 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registry:2.14-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registry:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registry@sha256:22e1862ebb8f7de923482605431522d7f252c2a3c1e60e97c11a8a926d29ca91 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registry@sha256:8d696ec48c12625653616b4e9a2253bd807f8d18d0ab601d100ea77663a2534a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-registry@sha256:06f8a45559edfe0f9ea341a96e78f1745e52f0fe48f5504715c0c4636031480f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registry@sha256:47e96bd50a6ad1f379fca2a8ec577c0b762acda93d4538c39a27e18533b3e15e |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-registry@sha256:700278f677185588dc22586b70f461b1393712141206e984cd7cc203ab19c4ad |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registry@sha256:272436bf2beb6525e5bfb4be49e38453187cd27957ab97d06843186e88191e13 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registry@sha256:e4bc83dd6ddda7275415735aa15adf71263cf7fb833b3cf7219fe7353ee1175f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registry@sha256:151c085f3ce4496faf00bf575d11b1d59335506d10dec49dfaf0572b0584c03c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registry@sha256:760b150cea8e47b0510e0ad6ffe65d9e13ba4c636de1040f05adca95fe2079fc |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registry@sha256:fa033391e9781e51d21adce427aa773f30f1cef5639bd3a12511e87624b073a7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registry@sha256:bcad0b5d7ac9464818ee5431f4cc0400c0a4a0853a315ea92478472beaaae9d9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registry@sha256:805affa08fa384ceafc5dc747c750a3331ef247c20d11f5f41efd26d518fb77d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registry@sha256:d4867e17eaf625ce1cc76550803bc62f9263a5bef519dddfa4be5308ed65fdd4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registry@sha256:51483e5ce3f024f32fa66b5518d3d8c2739c3b9ca712837760aa7f18f412f852 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registry@sha256:8fd50fc026bbd1f1395dc8c9841f307b8d5730b0a6e8793a28f7b7e05247479c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registry@sha256:46d851fefff7e6dd22dcade406dff8fcdfcd62f4c6d8c40e84fd938b81d3124a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registry@sha256:2b2dabea562918f4155f24f2e606ca26d1b719ea1d97c9fd0090101c931a7be6 |