Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.13-debian-dev, 2.13-debian13-dev, 2.13-dev, 2.13.6-debian-dev, 2.13.6-debian13-dev, 2.13.6-dev

Index digest:

sha256:93a2f49ddf9a8a08a2fcf59b6056689db56776d07a3a8dd91ce28ee660888b1a

Manifest digest:

sha256:9c7d444edee863f29486ef4fdcefecbcc62fdec6bf3eb53190d45693f9b10b37

Size

106.73 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:581c96cd18a79db2c18cbc5eb78959750d272de4822a9e83bd841ba479473599
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:cbefcdeca6cb69eea49d57bcfdbf586be1297507640ac5d8b9a5909ca8826d9f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:a5d852b9c3bea7188f5626a156efbbc90d0a911f43eda6989593aa70c14ed74b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:fb68b62b6022e0c52d384f033fc3dc169953af50dd9ac93ddf3b3495821eec26
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:efd3ae7ab1a74c41c1a35bcd3ea0443189ec606b0cf8a3a815622705e7ac024f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:bca52dad1383d7e24234f56403b6a19ae83bc34dedd6e659944a8110fc90e086
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:0f288a01c54379905e8ccf56029929c21bd54418882daafe44022e4e72e8e23b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:b5081799bb4c62e30dfd27aac5d31658feb03b324c9ecf411142c5a0df483714
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:089f25cf62c2a36f7ff9b53ef4ad0845722d25f8631d845a5f81c63004e46d08
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:1c4fd320f76fa4ec0286075611df97fe601c2f5ffba559145ec84ed46be3b159
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:0058b52bce100e50074490a18dfd7aa1cfe17f93782cbce54649944a65406335
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:97d7fa2d26a61cd503ef78092cd12cb0ce71f43d98fe4d00ea129b5540c1eae0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:07633a50d4cc5a0918ba97972a21d46385414c9cb9efda896eca3dbd6b6940b9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:1ffd93be2d858c5a4ae04fa8976969b0a1a9d1532a77bad8dfca2983f44a78ed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:d45eb8c082fa8d97d531a24c3d836e480bebccbf769d5c20a724b480d7a0fb0a