Sign inSign up
Harbor Registry Control

dhi.io/harbor-registryctl

Harbor Registry Control 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.5-debian-dev, 2.14.5-debian13-dev, 2.14.5-dev

Index digest:

sha256:c28a8ac73d9886d5ff8db607cf11516d4a452fe7c0eb1765820d404d1c87f91f

Manifest digest:

sha256:8547cf9d4b2f7b1fee91bf5cb361cde3f7afeaa25fe4a342937719fefc61686c

Size

38.30 MB

Last pushed

7 hours ago

Vulnerabilities

1
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registryctl:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registryctl:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registryctl@sha256:4cf54ca95877845e8048c544cfba9746b6400fdfdcc6bf42e70b1f91206aa66b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registryctl@sha256:8808366f3b7d300d49f2900e4e938b8c5418320d4068f1f6e76b57a7b3fdfb46
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registryctl@sha256:dad97e39381de05131ae4028c0ef1efc023f3b6f7ece9333e059adb676a6792b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registryctl@sha256:4381fd5a9428aca23d3aeb3df18ad26a4ae892ec9ea44a4196be35cad063ccc4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registryctl@sha256:bd17492509645c87c65f65e88e417c72bceb2e629c8cd68e615372e1a1a09999
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registryctl@sha256:200c0c24eb19561b29e27f4f0ed517203ce96c703e36907d267c27391f66a450
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registryctl@sha256:c715dd6ab1c885c603557bf9f53d2d64cc2658c71a12e4e5bc45f6cb0a378d2e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registryctl@sha256:265a7da50a2d290c5064740ad9dc92aaddc839c02bd7d4906b936b579ab948df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registryctl@sha256:c01bfa97f75010e0d2e3b56a2f94851085f1a2cbbb1761676849578ca8e24036
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registryctl@sha256:7449b56a386ec5223ecdd02eaedb9bb1e44170ff46d0d6957cff21efc6f68051
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registryctl@sha256:b2f7646e1a862875d1b1ed0f22b919941539bd2fc50b8e68a8d0455f4f82751c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registryctl@sha256:f0964b90e2f8ecb850a2c8b6ed1b23b597233dcc90b0bba226b28acc6bd4d592
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registryctl@sha256:279fbdba68843613f668818e3c3ef66c7d54b8c4bbe43c4ffb8efb0f5bad7c6a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registryctl@sha256:85d911f2b213204c6e00db71a8a88de6f2d68be2ae868d56824e64bb2b3e1946
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registryctl@sha256:eb3b0ddc175d93390cdc8c521d41c2cd2b2182ee3de5441055bc76d935283fee