Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.2-debian-dev, 2.15.2-debian13-dev, 2.15.2-dev

Index digest:

sha256:d9f155f271298690407836c3599be2835bea3f11971a21642d9f091e1cb181b2

Manifest digest:

sha256:b4348399e3c5bc5fba6bfbd9d663cc871d768826cfa3adfe680667c61608a994

Size

36.55 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:99cd73b20fec246365ccae2f1b5d5e831a8746315b288af0227dc647857a8b8e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:588aff4257acd41acb0fa2b562fffb6e8f7f476207ee4c714314c4f32321e76b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:322b13e1f23258ba4b9572352dfa5f6c520188707cf48ce3175a4e125aecc77e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:74c0c0e7c50ace6d280593fc6097c8c60dda7eeb0d776c20cb328ee7fe8b3d18
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:225046ce107133c156a6dabfe690beb85276d54e18eec41f15602ca62624113b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:39e30ea7d4a326dd8fd0069e172fc4dc8270de57461613ce42e9e5a48176c6a9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:a21dca433f2bada533a98830bc3bda7fa50fdfe33efa95116f9b8da8b6024092
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:d6b98d953d01c3c2da9280f8b3bf6902abe80bcfa79211707c23f685705a9e36
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:f85028d11252346cd9a637a519eb8180653137fecf0b78b96549e4d70c550102
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:83b6a5a6f3f78388f0cec16331ccf43240825684c56c3c19d8de7642d2178133
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:c31cb36747faccdae5c0b7d212a5e5779bafe4c3d276d20670e7d4fe3add1a05
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:b866985d7c69c9856af40a11d69bdc8af4672849df954df01622b2112c399a93
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:166b3e0d8db7526cdac90ff17aa7bc4ce0690fb4b4e9c5b1e1b55282429a8da6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:a9a9c7088514ee2cd03ecc8f9bf784fb738a6dd2177e7f4f4d0cfbec77a2f736
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:07948b01e737513d87ce52e10ba044599ea5362f07ea03c8b41f67cdc00516c7