Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.2-debian-dev, 2.15.2-debian13-dev, 2.15.2-dev

Index digest:

sha256:f1127656dca75d685e04725f658631a2d5a9edbbddb7fc5a4b7f26c2b0e21e17

Manifest digest:

sha256:2273856a4babcb0059aaec2c773c47f60eb87e6c6158b275e4d6b1a52809e435

Size

106.73 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:85d71607c0d922883e6684dc3b2ce3a1774f61caed00ea6f731efc6e6650bdaf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:66bcd664a8f37c20d5c8304f17f3c00719997013d7413b883d36b324f1147362
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:e51a5881d7dc016054d3ea62e4790226c77000786de9418b761a5f2df946710f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:6aff79b26465bb4d523017598ae9fa629bc3a05b25e0089a8c6481ff3f65bf67
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:d75b7a34dc9ca6c23d708dde6c33377db6e909537377b66faebec67633f46ac3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:e2869fee4fd7e972c4a09aae324a0b3b714ef7034b561d764d146bd52709afa9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:12c2acdbcede4145b1327914907f0d0a6fdb9161c8e9d64ac3deb8f7a1f548a1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:09b7b471da3fa3e8edf8f032e09662c7fcfc733e169927d5f5d9f0272b7758a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:95bc01393313c8f186611d73f4fca9604c083ae8d0461c00bd6a9f16730df7c1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:b47fbd1a92dad559857d465071755790b6d5e1bc42075b0725a1aec55f4b5d41
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:f44d8b6b81bcca644d7f4316fa6063101ed44372f2ad258d74f8e2d3309d338b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:92aaf0fa4c901c858a49c199e14711ae73517289bc0e05d9313964f607465603
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:2825e7edc8ea95b8c701866cf3676e4c8bd137f8603014baffee2a8378b8b890
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:39a2058a0f9b931f2a7612dab15131182a6183fead9caa0dabcc6ccaa399e383
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:48c9a545d5e484c3d742e7289b7651e8c117229e009d0c73919fe77fe274c21b