Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.2-debian-fips-dev, 2.15.2-debian13-fips-dev, 2.15.2-fips-dev

Index digest:

sha256:9e8857c08160f9221cb122189131d5eb1f4c9565c95504cb4400796825065c6c

Manifest digest:

sha256:a35eff4574378fe267945cd29768218713968f896552a5cf8a792e96524841df

Size

37.32 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:f0a9946972138c8cdfed1699de2297201b501d49ce7ae6e320e5563753e70d6f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:50598dbe6e54f3db2c8f7a40bb36b768a4fe143d9dfda98393b362f056c460c9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:c5e0743c0be399cd8763b8beaf36812393646a719fc347385550554bcc4464f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:ed9103ce009f724e0c271a87a99694960fb1ba1e8fd8295135def75772555812
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:870bff960818e89398271e15121fc598c6bc8e46ad7f419d801d6934d28a5522
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:e92e8916d3c04cb9bcb100288e1cf48a753b5ee073b2d2d2e3dc00e1038baaeb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:d2c4c0dc8db88fae16283c766c509c0478949001a752887d316f1ec9275129e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:831a66e8100e27af102d35d431c0ed9b19ffb574219d65cedcc1a3ec85226464
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:7e5ae43c5442e1cc20a72f1b48934eaa1b40e1c7e36adc52b74432705b8e1682
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:c0b2ec7fe33e0bef672be9278e23209d7411d6e6e4c28bda3044d7694b73e340
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:9ecc386430a4d4ce24fe900ff8f8281cd7159eafc83db4e479f07a6a4058c06d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:a6fc8786df9598db297f34d5ec443a38b4d2788277b69828d9d35017982715e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:2786dbb0fba765f376df117be4541ff4151707bd60240e9a5b6bc0eb868bb06c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:05d3d2fdbe7b3d5ccb93482e28eb4e0c60446c332061ad378236f124f7b957e3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:ab7ca816da502e764f4ada3a98e145a5048f9f01b5bc0823514d53bcadf772e3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:c877297dc993e17904992dcd27c487647c4579713e7ab496a74d23e97a20103a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:69da94c1ac58eb3f549ab3fb35a6b1f3d82621d8647e24447bed0216d346f8da