dhi.io/harbor-db
2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.5-debian-fips-dev, 2.14.5-debian13-fips-dev, 2.14.5-fips-dev
sha256:417cef18822414cfc6c2cecc9224479082691711db8cfa6199ed98409a561e62
Manifest digest:sha256:514c57ffac2659eef255ab944decd33dbf0e688f76bfdf8e1fa89d494a40cbd7
Size
107.50 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-db:2.14-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-db:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-db@sha256:4124e78be93db3110ffdb59f4dcb04e6b7b7a9aef9b0d4d87a2495afcf3e159e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-db@sha256:f50255a1937656c4e70cb1342c8e09f8b34611eda78fa77ef77f1958aa62aaa1 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-db@sha256:ebfddb51bdeb9d64da650170c50bf921e6df8edf5bee173076a364e15a9a7e17 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-db@sha256:a2eb61c9c434335a23e7be3aeed25ecbfcff4240c4f29f109c625118cd176086 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-db@sha256:2ae585f19b336e4d6008dbafc9a929efab36e54d215cbce627d1483e16a271f0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-db@sha256:de16c4c200f3552f85731cb8dda81cd6bc7722274f129122440eef96d7e3cd62 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-db@sha256:2067c63affb677b7d22188af0898100e76288104575458d3ba93189e5093b512 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-db@sha256:aa89cb1a5217b1a22e136ab5a09107666ddbbf2d4b4378f9c21bbdb344c53c47 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-db@sha256:b7bc8e29c82cf34f159a26501129fdbbe7bd46a77d2649d7e9c7817088920ed6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-db@sha256:2a03eac4f840bae6e42125e9b4f2294fa8b34436eec58bf185721458432b6833 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-db@sha256:30c8917229cdc6e9e509502223f93da1add1f6d7c203dea31d3b12dbc1abea6b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-db@sha256:2be10918d6ee74ec2c15f11c4a94c382582f35e2466b513f9677e76b14d365c4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-db@sha256:5475659378fba393503b86371312e770e4b966cd277ba4310f07221e6df66eaf |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-db@sha256:e24e26e0d96226f48689142698a73412fdb18a4ad9da45f7ec130b989c248501 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-db@sha256:dffc6b75b3650667383a0204955cfb873a195518e95595ad629a8b1b5dd84fd1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-db@sha256:6d8cfd7676a8b7d831573f604ea8f70cfcd4498900bc7fe786b9bf6098bf9b75 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-db@sha256:4cbe8033568270419b87abb205275bd8d3497585d227096de2bc02f51001a64d |