Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev

Index digest:

sha256:1fd4c72ce83c718b81dde046701305b619443bc33a0f8dfe199e2dd5dc2190c8

Manifest digest:

sha256:76fdf6a3fc77ab9b7c38e86cac4f0cb657235a87292ee17fdb5d3e50c36dc89e

Size

107.51 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:a04329ad1b093b2c16938d721dde9ab519f758b970fada619fc15a68ee13191f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:b7143b59e6018284b1e44c39b80703cf2c4009658b69d42ec5db186a45648b8b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-db@sha256:4a83bb206c94b09f3a04c80ea9e05a68a2832a831a41365c6d3e50b1f3269495
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:2e6d0538490c5d749be97af4bd912e787d41d9a4b921d967bc2cab4a506b9c16
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-db@sha256:970a28b7accf8b9d9f746f31637dc6d70a00e5c24c5c5cb16eba9b117c3d562c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:2afe082eba70abbb3b19fff10d7561d5d8282268f3b06d70474462b16a92c156
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:945bd7f1689f3aadf2ac4b7c3f5c68eefa7797880b7f542176ec9ff37f9b3880
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:6f4946c8c90d115e974e937aae9ef283bde73210af0e1dcee286cb3af311e95a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:ecf8b3e8d80b1313b6c87f992006efc9a61cfdb2c2f764eb52a8c01a2667efc1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:5defa1dcbb27c8deaf20a6a7d08964e6eb5dd9076804c299c0bbb12d6caac85b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:36e8d121865cfcddd2fa06c720c93fa54c4096c14b9ea5c266444da9e496ff43
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:6e136d72fbb0e76737ef517621443b7d47cd98ec94ec86a1348d00dd533d2971
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:e9383730aa844f3103133feee297b63f2e5a3a1394f7ca075c180571b7dcd12f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:a063263c51c7891edcb206a1d736445b6720fb082220140a09c88006a41fee5a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:a3ba086a2646dcb986bf08f763e3fc8aa69a2750b50185a700883a95da3b620d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:5c21aabf89af47f6cb0230567b40e4d83605398b57fc4d71db6fee54843913ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:c86548fe46db642cb43b2f9116bd9baeb27a54b13c337f156a9c67c29bf2990d