dhi.io/harbor-registryctl
2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.2-debian-dev, 2.15.2-debian13-dev, 2.15.2-dev
sha256:f4df8cbcd5c2f698f87b7641dffa6ace3d77cf928bf2b2c5da6bb1ba7b95d6b8
Manifest digest:sha256:504a75e0660cee8b2fefc32373f817c48cac5f02f59a5cff51e0ea66083ad68e
Size
39.03 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:2d779096f6627164f0f6b19e3c4e34f10cb0c5f1c3fa8b03f3ad1fca0ac817dc |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:9a3ac718b3f3798ffa8fcb75e6698a8d3effead8dd03b436d5daf67540e047a3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:0f12ae30c32782142dfd832aee7c1d7b46d7e6e143fc36482fcc983d13e321e8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:852ff335ad002228aeaf4b60625aa17bedddeaa89aadf5bf012d279fcf34ff63 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:7fbe401fa456836369c16a4dcf7349a31e54340e828df1b72d8c4ce6065ec2c4 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:332d9557a2952becc9858a0c59fea011b2729a11910629990bd88065e99e698e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:3ea29792cab12f8249c127612ed71861a28fe5e6243012dd2636794acd4db3ae |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:8d08fba0d8f62602978846ab4e5c40206b4c4d58a518bd25e6297ed476aea6b2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:73b5a9ecfa2678bac799513b84dd5cdcd01bd2fdf7ed35d2027b67752507a2b0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:9bf02e80c3446e0fe416c41d2f1087b3c94493420ed48c250ce313b75535d4ba |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:963a1f0712502bb9c401aaf7693ecbe01a8fd61a7d5562c92877f019163b2864 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:05e0b5b071aca56de10e0d3adf2926e95cf7f55caf4e1f00b4bb446f2fe71fd0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:09033b3e4bd0837b7d6760fdc517cceee27ba944be24d67dd0cccb8c6b3e076b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:c63edcdb709488dafde864592c8fb34889c1db1ff944a1639b3eb75770cce0d4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:b3b00438daac7a1c1ce0390fbb9d5b3be1d6ab59d24afb3566d3eb52228b86e4 |