Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.5-debian-fips-dev, 2.14.5-debian13-fips-dev, 2.14.5-fips-dev

Index digest:

sha256:21c351fcdde99123b522968bf123a962e7471d4b17dfc44a6af41c4b5e1bea7c

Manifest digest:

sha256:f2a165caf02038c7c040799f4b63610b12307cc0f8902d0f8a54f17d3c44b00c

Size

37.46 MB

Last pushed

13 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:c0e8f0f7719293ee84d20cbd129546e99993593a4fd50b5806d6a6567556d226
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:6c094d008427696ed494ccfd0cbcde524881ddf71313b066ad77e22f78b0c560
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:df9377355ac61338eb8c5d0d6d9d6eefb1c5483198e7eca91ff566d34d62148b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:fed1aecda2f7ae8a275b9acf54f54c95003b91e1ab68a9cf6aba67d6886c5dd4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:0289218c41dde97f58c8acb614f01afab13502be2b36635c410d1fd9fafec510
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:02f9ffc786b2c81c1d07ae95ec9785192d980d2ff529ec038dda3b208beb31a0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:6b7e64e1807392ce6c6154ec9e1102465ae773bc446940802efb90a040a2cc44
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:9baac11342b59e5442db334cc6213de5b7d3089efa2bb63be32422d46eb3f43d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:d943e5605e9507e96c84fa70f89c727102da6774b5ec7a95657ebffedd0b2776
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:1e43546a97fb47b946040d0d655c0bcd5bdc561eea0e706b6e72137443900ae4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:85db2bc472f3a68c888e0ad75af9cf82bc0bacd03a16d6a5b340bf8b3824405a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:fe59d0d39544856affea7a984c969e716b7928ede14e461608026b75b948db33
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:45d25a62466e46079078aeb393780daad348c2a9aa389fe4e14501b7a1ec567f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:6878a75e6439b2712f3ad4d9236e9130fae51178fbdbffccdecac69a3a7a8f38
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:645304688954ab51f51f2eb53d7cecd960ae95e981822a4e7dd27c566df65ebf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:18c6d4d9c4e9ed21f5d46e40a026c8c3b2cecc8c17a6da2d5043c03d7089ab91
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:659307ebc05bee2167faf4e54b7020fa81463c9ef072f31f212397afbf66a378