Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.15.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.15-debian-fips, 2.15-debian13-fips, 2.15-fips, 2.15.4-debian-fips, 2.15.4-debian13-fips, 2.15.4-fips

Index digest:

sha256:4c6a5b07b5e0032454554852a51f09931d254bf85b16cef584734d2d8cd83dfb

Manifest digest:

sha256:a64f54ba796c821f0b59854e26d5959aab5a4c3baa6cbc2b04c8a876c31efa1e

Size

98.00 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:f5dabecf9b3f615dde9d3a07a4cf1a0f7ffd2fc7a2224102d8466dd37fe96132
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:a2c75692c66ed311e49ec24ff25e50ff8dc018e6387b3c06ee9c30a21cd991d3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-db@sha256:3a1bab5d78a13edc9632a7bf8304d0013d94ce3460f749e4e4d01d01bea023b5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:af6907c00fe476e5905b700c7904aa48c62ea96451ad4c0ec0c68dae664d533f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-db@sha256:7765325123b8d5b6e431d87e66d20192ad16a3b6b2b40c44ddd15c105a601e54
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:c8f975835ff66a344b213ddfff4efab73f53f7ce94a2bb2696fd5b4a743171bc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:e59da7192a3ae6dafd1855eaf6d12ab313d9a7d54541666a33d9372d569d9151
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:8d5c6c42091b72be1d336136a3e47296eb03425c0c30d1ef523a4a6b8acfb8ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:9b1b9ee6804be3a6b2fb8c525851a487ca48ea22c01ea051d4468e109abc6a0a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:6cb1c52dfaecdae06d25543ad84c5c29872805144c5d70c067629b8e057167be
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:46c8f7c5001ee8838105e6e2e2c26e9a85e7bf258b460dac1e29ce272dc7ca85
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:af2e53a904ffcf096435f36a98cd1ce5877a76adfdfd31de30fb4296be7c671f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:a0632ebb124c1a99b4b2ec1e1f270a661dc51c4f0821fd4af810b2e989b450ec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:b4f212821f7e8482fb85af70836b626636962f64784488be687210f57547df39
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:b7a0c1947b407e041a2a4a9f94fd0277d0d1822af77e956fbb29e3e081397b2b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:7888055b430dccf778c3d3ef78037d715304edb61ecca13d930eb5b7e1bbd4ec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:5e649fb39d89d8f72b9929215463668ffb80517ea77aeac574a0016b2534e313