Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.14.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips, 2.14-debian13-fips, 2.14-fips, 2.14.5-debian-fips, 2.14.5-debian13-fips, 2.14.5-fips

Index digest:

sha256:9cd98fe0b5448d0331fc223476ee9d91ddb206cc7c7665bc121955848ed95b11

Manifest digest:

sha256:04125b6c154f2648e9f43bef60c8f44b3c4792f3a5e213e81570e0f68329189e

Size

97.43 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2.14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2.14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:8eacb5a0eb63a95d0c5ea9dc87c71dbcd952eea4ab9ebf4e1db799e10ffc48c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:954c55ef2b1fd732bd5748959a2b780a3376c5dc01bffcea0a9d0578f1868c24
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-db@sha256:3d7bfd410c176dfd480ae7a62a206bbd06259537d9fb415d6b66ca87858fe7dc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:47ab761f4fd20caf50a7f31443ce0ddcf9ddd5239fc285cf514f940279484b6a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-db@sha256:ccd1f76083addbdd72f18c8e4d9a1890fa72fe5607da2fac8d78082c77bfdd03
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:0de14f6c929c1083b3fe3deb51b244ae9762852c0280f0eadc1c43ef661cc01b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:2ee65e39840c3764efd6ae16fdfbe48f49e3ac861b236a372767273d40db2b01
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:6dc424eadda954ec5a53e2c010a16fda7d2a2c54f91dd22bf3e8fbf9f8729f99
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:998b310752e98a40a55fa5b77febfc943959532f2f0e76a4d59597abb5a49c75
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:a3ffa3e9adb80c78e8ec3c0721f4eb74b8bf731706c6ef8a1576f3ee9944d4e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:cde8d5f54475f8f40d2e196acae95e99efcff8a8dd1dba6a4292cbf3094c03fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:cd7435bd0882fae2fe5a4a6bf10a52460de7b0476fa19e0d86aadf982dd2db7e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:9f027ec9a19e8c06c867726680860c727e68b1b72531e301f2967a805aed7ccf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:3d101fa1d254eaecd05f45d3ae7fefc12ad604718361d2a3cb60452838c9eb7f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:4fa8e64cd44314e0d7e220412a6e1965fe95582cd2734e8ab62e875af8d02708
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:10a4d99575c8b4c9c2b0af35fbfe6a468082863cec6c3861c326441f81e1bda2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:d92f9c5f5bfad67f6a3aefde4efd70eae515f550b6369078f34838aa1a7f9191