Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.14.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips, 2.14-debian13-fips, 2.14-fips, 2.14.5-debian-fips, 2.14.5-debian13-fips, 2.14.5-fips

Index digest:

sha256:7df94751572afdbf42c594dfd9a4230f75ae2244bf2330fbc7286d9f3fde7abe

Manifest digest:

sha256:129ec749e15dcd8a7ee4900bcf1597131d6b6418e2271adafbb910ec02165416

Size

16.03 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:3a33f21c34bc19407a0cd2f0883e6e27358b1c654f6e403f9931defbe7adaf1c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:b8190ee04b40fe991c29f2f1ec9a7c9ee76a2323f155b9ffde4f54f98f205f5c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:b8cb4f4a1d103fe3d5f624d0cb885b73572c2dc097bf1dfabb507e132a933000
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:980401d0d8b5124626941c886714ac88fde49263aa3ecaf84b8856dd714851b2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:fc3f66dc1e206d55f48e6b07ad08d4ab0df8bb19d179c6447922f73abee52770
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:11e5d0f8b8df17943992ed2434799c29a350beb2c971fc48377a62c00a33ee85
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:ce8b2f06ab8c7f17a94acde1aa37b01b2e72a2cb5efe03090c48788dc8ff000d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:ff4c489fc3fd99c34652a069518702b4a2405412d6127fc48f0330069feb9254
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:5484954da6cf18107614f3bd7a01b09c139951e75db9404dc44fcb6fc0e2bd0f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:f8b1ba519903013b2c337d5eb828816177b7aa33419cbabb3381b8dab1d1239d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:d434d7542827a8151d50c9bf1580c9100510ef4a3852b66f2153a805c6e978ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:ca66d0ab22e7a4dc3f81e87cb2678ed423a5196d36cd548293362bb3ef3ac8ba
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:c52e73737cc734d44f5834f2b3b15891a906a9d94fe863c80e0e296c370cc734
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:8a065cf39905d5177b6c2650944d97de7e8fee00af679c73d228d934db30cf8c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:21fa786bfbc6cfbd4b015e79638c7502d1b217cd3117c7554ff02b8174e59d61
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:f88fc707ab046ec909748957a95add1bcc1aaa827676a3bbfafe8ac5a69e328b