Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.2-debian-fips-dev, 2.15.2-debian13-fips-dev, 2.15.2-fips-dev

Index digest:

sha256:a02e29488a2e449fa1dc571c937904d31556d1b8edb4842ef4df54bedff2e2cd

Manifest digest:

sha256:971ad7c2f8e1233682d5e6872d0482b2fbbc31ab072d937a510ae323fdb7c716

Size

108.09 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:c9b65551946c80646696680ba389ea4d896e05cabb563c07ca0978282d193fb0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:02bee48f6e53a0b3dddd9b4c8806878b391c42fe23fd380485978f6b66424f60
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-db@sha256:8cbb33a93d0bfc01824806a49dfaf04575dda90bade50cda6a8575f21740ccb1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:42b162d978dbe966713225e78303ff5624b844b9fefc7459f986fd0b50be9fc4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-db@sha256:84b34635c1fffbdbe232cedd3d149b9e414083d5b62f934d36853bbba4ea1495
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:6bd4600197f427fcd20b61d6ef17b52a4849e07b89d66832b93c6f0885c176a5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:2cf6b2817b8ef87f7a7788d89daca5247ab03a38cadf12ba2c85456a8e9a86e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:ba6b7ebb14c4c2b1bfc9adca0d10aab25ef4abf0efaa3418587301c8f5b3699d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:b663fb51a167ab67cce65bbb7b1b5ecabc9a1f66fc385b67e37c19ca53ff8cc6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:b59b9077702966dd7fd2c90448837af49b2a20e9aa70a84ba81fabcace1a1b6f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:da1e25cdc978616d29c759c6dd82b739dd9ed0838c104cdbe49f7be8f541dd17
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:b44f1cac739631e25b8c70f6fb1c9411441500733e0c1f9d9721cf851789e777
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:ac5f4ef809e7e9859173f7dfec70b6f26575a037199335633a5f2ed0ef45f1b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:66bd11cb61ca3f822b26b1b72e79275e06a5c16b10aa77a8445603ec653e8ab3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:804aaf2af5fa82dbbcf562927fb5d467d8d1105a51e97e22cd873104f0dd0e5f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:97c5f377325ab3fc3c0f634a398defad10cbca493f54363d19f7e01a92cccbda
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:2255c218dceed9582bf5eb5927ee3c8d639ff5c527e7c4b21315ba6a1cac95f5