dhi.io/harbor-registryctl
2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.5-debian-dev, 2.14.5-debian13-dev, 2.14.5-dev
sha256:18315dc9f2dd0c9e225982ad1dc932d60de7ecfabd8c1b1c1b799bc64d86778c
Manifest digest:sha256:965e2b50389938a36e4e047569e785bd04f38fd2d48e91727e78c7f350d20b23
Size
38.29 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2.14-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:8d3d089d29c512f5661c30e2aed342df007c715cf30349aa09709b6a70d184f7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:d19b077dabdbdf9f0d0c23e7dd9b654ed9ab883ef5c7565ef17842f800942eab |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:9c335085e9f529ac7815a96403515e38a2af4484b1cda0b4ab3f9f19791d7509 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:cd1ea19dae919f4e54b5c925e49cf377b439c1ee4225e46fbe578c08015678f5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:6975b052eaa607218b553f9b02a53bf5e3dfe74b7305a6de17e1714c2323f71a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:7b660a4e636243597ce9e363a4ceca20cbc2687a93706b7f9f23d3f9c0e3543d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:deea6281474b5f2ebc7955dd18d3e43d4043b44b11ad2835e6a65b35d1a673eb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:422c41a4216de95b3e4a5750556f4f63c6b1c6e2e2522dbe2bb5acd7def2a049 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:668dd9042e89cf124402bdfe2ac63ec47a63f5f53d81aaa2cdb4cfe0b71d147b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:8824df82d861c4ae13a2ce9ebe2c3d20ef768f304847bae4c46806e461a2f740 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:2c57e1c99264967e5d1faeb99765e09d7ce4ad9f0e3067de4d3257b9211ed872 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:3ba15c23c375f45e6d2c52c4213f381e2924a86839c1cf664bbfcd596f0a17b1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:3b1ac467bf4d023ed6d3ba2d269283a3a303d35fb9a0756a68828f38ad3883b6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:ad2564d3248384ba2985e6e56288aaa7d77a5a95de8fb7155d6f541c394cde33 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:f9438008adb30ec8acbc77c8daafff5ab4b03ba854d25e58dd0eb17b4f0d77c2 |