dhi.io/harbor-registryctl
2.14-debian-fips, 2.14-debian13-fips, 2.14-fips, 2.14.5-debian-fips, 2.14.5-debian13-fips, 2.14.5-fips
sha256:3579a8fbede0c044f789c4970c7fa06106524d335f5849aa62c213a1180663cb
Manifest digest:sha256:1070188864d2c748ec4bf0ccd1cc5a72d8541d7382cfe92863ef4143069f7ee5
Size
17.01 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2.14-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2.14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:7d585d1909abe8e862d2b26fc8a9f3ed7def0c39e72d15320162abf1871e2ea5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:34e603e60c30466950b1ccd97917374a5c72054056d0d0aa5b9998169c926cc2 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-registryctl@sha256:99244097072bbc7020b312fd7f79b8a8763edaa0fc4ceb47b6d83fa1c4d85bf9 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:9cf99ea59f5b4c3859ec062452aa65ee89d89480dbeb7b0d3fcfc6c088f7bcae |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-registryctl@sha256:1a52cc6a8050a8cd6706dae84bdb63baf065a24ef82315e5a6485d2f1738c208 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:c53d10676e87e0f3cdcc270fef4951f9b2388d4b7d309339ef2d0fbac46e12d7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:8a380d95f56a5d0c88cbbe37362b8c2832be3417cf4e7ae983d1b16559e784c3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:2526db4673169e85c897aede62a27d56fbb2ac692c6e86e6172bdf3c3738d886 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:80ac31f2f7a7cd252062a91bca857c559085ea91baa416a839ff7a14feff193f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:de17e1ac0d2904ffc4fe1c8d31e0b137f24130b36b9fa003bb2ad76e4bf5f2cd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:b2f4b77641e9420f04b85fa89c1da4555e11d7ead505d2749dc3e93d5775470f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:81191a9067826486db47404431de88efd73f4157a01e18ea93cacd117abccc49 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:16a610fbf61896b5a3f28679e5810a42bb2c4decb246242922197db06bb44ab9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:fc49c0fe8cfae3b5fc57aa40d3476dfb0a5b4dee21448692bde33db70535ec85 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:88efc2f4e47ce30a493aaafe7a35eb98a82052202f1c25e9995553feea52fbb1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:0167b4858621926e3bb456845086c85a7fd5c19153b6731cfc9c7b7851c97b34 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:306eafbd31531fb0e8cd7be6ec9201b7cdef2d20c427d94dc440197f4737888c |