Sign inSign up
Harbor Registry Control

dhi.io/harbor-registryctl

Harbor Registry Control 2.14.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips, 2.14-debian13-fips, 2.14-fips, 2.14.4-debian-fips, 2.14.4-debian13-fips, 2.14.4-fips

Index digest:

sha256:7d5232cc40164c089678c5c281f1e28e8365a9d3542838b2d7d34ea1503928a2

Manifest digest:

sha256:d3c7d3ec541daeba483882ac882ba3b90a418305743333d223bc72f08a959b12

Size

17.01 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registryctl:2.14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registryctl:2.14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registryctl@sha256:be5bbca7f6d15ddbd86da4d1266ffe385cf4291624fb11ee28ba2179053ce75b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registryctl@sha256:c0dbc3f8d3532668028181d027cf1d8f8dfc88d8f5294f3f40d4270dd51aec2e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registryctl@sha256:9fea9ba1e38810d97ef148b693f00265257edafd673810be9c1b2670c9087b43
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registryctl@sha256:e5182d634d7e55407ac43254bd4ce18a612ed07bd035b15854b665a22fc30661
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registryctl@sha256:82e5a83fd3ae3a92ba09b1ffbda95fa5e27888ef9f816c4de57dd00fd5a977b9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registryctl@sha256:77d5c2fde2230c71db39d4dc32ce5b4d427ec1756ebb9c3854d245dc2fc0c47a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registryctl@sha256:bdd9976bd32865ff10048e245663f97c800c2a72c96b61997089a7a69f487ae7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registryctl@sha256:590cce7305ebfc5588e9fc9172dd8b5b9ce85b9cbf31ddb4da915df1231476c0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registryctl@sha256:f1ddae677578eaac6a63473617d2992811fbfdc36a9835b262bb95c82db5e97a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registryctl@sha256:a32ab57353477cc91ee5b93e465db059ddba42ec0eccd2a5967d59ae4866c4f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registryctl@sha256:4da4f4dbc9921b33e31ac08a9c02a2f3c74e4ee502a6036c3087d995dd18090b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registryctl@sha256:7e9e033fcc175fb14773b1863cd00b515e5ceec199e66d488185ce048950f3f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registryctl@sha256:fb9516e8125d5e0358e849772e83fe58e031bb0b061b370f3c5722efb72185a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registryctl@sha256:0fe58a9a8a2c0ab31f75a006df124c46f75e6beff4b937fa9870a9536911000c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registryctl@sha256:f4ec53068d7b6b615982d117b65a085b4b78c14a917921fcff0aa625599ee9ad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registryctl@sha256:8dc48ca37a2536646218a8a25bcd5ed688ee3b600245209f68637d998abd2be5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registryctl@sha256:0aea55664d783309bddba8a3ae03935f6df54a56dc619c7668a12983b9fdb118