Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.5-debian-dev, 2.14.5-debian13-dev, 2.14.5-dev

Index digest:

sha256:aacd81bf0fdb59db283f278661b34a0ee220525220e064f94d569022c4dae1bc

Manifest digest:

sha256:3d7534d7045befc371d022debefb98547521392c63497bea9e824f30e83ee4bf

Size

106.73 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
1
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:9c199016f2a48e37dd89cedf0bfedb8ddbfcdeac94beba2228e7764f6642850a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:cce474cc7943a0768f17745160f26742cfbf924e150eb625019c9e315084c190
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:bbcb6736dd978de007d50c01df53ae0ca0718091df0193c8304fe5010003a6a6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:8a67bc2b74b756ddc168162d7c5c0baee13469f67712c0eddf8c594cb808c17f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:158ed03262348bf04987a09a8521ab74ea67bdc71b2a2173e962c351a91b03e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:91daf10e116eee53136e363e4e4d9d8a13f1eb34226101ef95ca0c18da850abb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:ac4437604e74bcc6285a6d099da2d3e361ea86e1af07e1ffcff7f635b29dbff7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:942e28eea92f5958a5d2e23fd49e352ee4b3b7e9c6e45185166d024b49d745f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:93fb2ab63729aac033f6d3fd2aa542ce29f2416876811779028efc5e6d5af0be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:407404cc701ae7bc823776e88fc192c514fe66800e530d41a3821de1e943e044
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:821e0eaf479ea0af966d723bab9c31e25670d764eb6e48c1ab8973003bba5bd1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:73991a19ae6db56cf938eb0dd0628cee05282ff94b384e479cafa42426088a51
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:f2a7ce955864c4586ddf3bf68ee4488a27820c4446584dcd32399862dbc6b688
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:8b3e0460709b931ec7dda7952ee8966de3505e58b3f38f85d732f5fb4179c303
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:61e85309cb6ccf51ce22291edf8179bba4c19a9fcc5eea1309ca080648d9ebc4