dhi.io/harbor-registryctl
2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.4-debian-fips-dev, 2.12.4-debian13-fips-dev, 2.12.4-fips-dev
sha256:37d63f718c33274ed4453acbda6dabe25c5fe71fcb08c2dd0fe967ee13424dd4
Manifest digest:sha256:01b4abaddbe48e903df50f03c4ca13bc609a50c7385133975a3e249eb921e813
Size
39.01 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2.12-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2.12-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:e1577e474d50a09e4788e0af90cc36e20f24117eff47b59f52f9c778ac8e00a9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:633750558044cea04ea9116ac6526ec501ca1310f313aca4d759ab42e4d62d29 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-registryctl@sha256:8cb1e39ac9fa864ab1a6d99abeb19b72efb0290196865298a585efbb62e4c2d4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:5254225386696ce7bc5c42c9569fc8c567963edde7611dca0f0cc32d8d90152d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-registryctl@sha256:343b409b977d8a134d3252963d9bfab2a1a3ed3279531aa042a08061391eafcd |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:c54cd22390f7cf42f4972da87b897dcf781b20f833ba2b56daeeb8651e11f563 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:b68ac19c5fd281a750dad75cccaced8d2618e16f517deb28e8309278f6155519 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:78ddadf92b98ed908c5b592cf978db365b61df7e549a73bc78f7de6c4a8ebfa5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:8c03b579debd95a0903ebc158d752b3283c8dba2292ea4292e67359d7445e62b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:6cb11395fe9bd045be0ceb163ab50c32cc56785b7f3a5fdf30078abb06cbdc6b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:9c06f004733020334e1d4014e84cc2d14f5c8e50dc6ab59417acd204cd39e387 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:50b00e6bb6e7705a6cd7aaa87afd6115c02bfe467686b575a318a44c565a3d54 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:98d970d26697a80b92acb3eadbabd0743c526e51c02b79b9695fd412de81060a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:1aecaf90348d3b74898761f55f0bd26b1378e08e2f494b24a31075c85703a0ae |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:191c85d7e372df6a0d64597a3a659f51b8949daaafde3a3dbf54a8d74fef5d24 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:69fb354dc1f2494eecbaccebd2e193b4ad06a83d8a4ddc299a1e280ec7834b20 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:0b0774095cb31579a9004fe62ecd9361d906ff01ac3ef70c93973f4132235830 |