Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.2-debian-fips-dev, 2.15.2-debian13-fips-dev, 2.15.2-fips-dev

Index digest:

sha256:c2c27dc3850099d196a0dbce8c2028b56b891c973ea4e32b2fc647b110023a5b

Manifest digest:

sha256:8ad96fd3d1535fcc6b471968c1abfa6b3f7c43e9badaa372ab7b1a7c7e3c5f92

Size

37.32 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:34de8d0dfd55b29b0291fd5b72ea3cfcb7d2d0d911e3dbc3e3e8062ebee8fbfb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:6abd1a8e1c88d74d995a60c06e9a557c26610a9532bef6086d9ccb909abb586d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:d42a4008db37c8e4dcd4f26d3fe920d2f6d853393e2953fefa4e8a6984432ab3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:f11e78c22be81154cf200dd5e36ec6aaf248ff6bc1d92b7b47401f35c7218467
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:3e4a85e17bef16b774661d16e729b5a484d461bd8985bbdc11e6f6b0dc863805
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:d2bb2dc169aee6ca35466e6d2adf9abdf3e597432abbff7dcafdc6aa91ddf012
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:a74705b183003075c902debb17be77f8548d4fe54ff7c513729155c58b07572d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:34e9afd946185eb4bf0ae36623e9e32e627804324ae8776c0c2fb068c6366fdf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:29470a2d94701dbc368c51146ac48f5a3392df1f7f9bbbc1506daa17af9b0f0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:b6d5601fcd1b3cedb153db1ab1fdbba41d86a58dc91fb537f4542b1c7b2fdde0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:f9b4d177a972ed65de4e9a679e36b2f2bf9ea614980ec4173f928a9be545b469
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:ebc7a649c9c14aa21b4038b46f823c7cf0bae6b8a279d31339c61b79599d7570
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:6dfbe33697ff89bfd8e9b4e5adbbec9e9adf47c055875baa616b4c318af67218
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:c71afc8a1b642e093b8e51b6c71ca3d83fe7fca83aa13f7c34b063d4150fcfaa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:68d1863234742a37532fa159c241f661f1ed8099f06e9badd48272f8b0421af7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:fd9fbbce8d8c9327b98038821678eda293be3612b4e89904f6aa038e1b6d734a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:50bec39a20907305caa39ecd3573df0e35534ec4e810b07e10df0f861d154984