Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev

Index digest:

sha256:596f25546c83b5259832f47461c6de83856d3ffb09d6862ca4bf24cdb10242bf

Manifest digest:

sha256:581e2bd21fc6af195bd3795d24cc97c2632b9eba3564b7b1b1cab49a2e6ace14

Size

106.73 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:a65f4d418cca5c1c4edf709be9629a8ccadb1a79ba6d44c0737ab3e216f53082
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:283009a2e11cc95cfde1a40ae72eb62fd5c07b26deafd441c2b22ecd55197fa0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:311ae7690c05c77e1f2e512103af2d27848986c37c7de927d014e1c687636075
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:c473df795545f64c186bf4179fbed6089734e1c134399b6aa9fd271abd08375f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:6d5add04bfbdf8fa91d6ac0f5c781e7806380bd342a688b557e0115bc4c41abe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:cd646e86e57f026fd027548f8c3837558d6e639d377306c296bcb331fc62d01e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:f595a565018ce5691a798d52b8e509551eb63898d2c2b97af8ac0d1300f7085c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:57f69dc2d5ba253e5f56d31bb76eca00ba1ab244289397743d8aa6868a825c4c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:ef830d6968ce817447df5ab49a20798f3f14428033ce247e0c237c423408d9d6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:788d231b66c9ec9c2816eae5107391d35fb5c6edaeb0afa07abddcf58c9b917c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:96dfbe71af4bd8d8b5ae2af236c0a0bcabf5415ff66f0160ce381c20903d4dc9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:b68b5a7f2b051fadcab167bdfd5fd6ae691864951769fc1016aee76b08997bbb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:a47ee81c67d9f73f1f792413ca67c18a8aeb54ed9b60d24a6d546909f160b27b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:c010f5b2aade13774abebbee77b205ad3afb685d5f4e853df323786e46982fe5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:58f7eccb6019ed8152a2f4495cd3543d9359ac6a489174136572f78d55a820fa