dhi.io/harbor-exporter
2.13-debian-fips, 2.13-debian13-fips, 2.13-fips, 2.13.6-debian-fips, 2.13.6-debian13-fips, 2.13.6-fips
sha256:8647fc10e0d31179220c1a58d3964768c47530c02428b4e40624d68a16a67692
Manifest digest:sha256:c2365acc59006a390eebc948cfefd28e63aa285a18cd4e6639933db5be3b6d40
Size
17.60 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-exporter:2.13-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-exporter:2.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-exporter@sha256:4a17a385db918dc5fcd144d9e9317ffbcb8ffe61890a0b10764e4f3d1a436d80 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-exporter@sha256:47cabf0fdcc01f0946f3001c4083dc4c5f1a87f112cc9d3421159ce6f8209a51 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-exporter@sha256:dae82c5415186e0df49f831e3a0a173cc6c30ba97a8b606aa57ca291b16a2348 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-exporter@sha256:dd5a4695726cdc4648c300d41ca33f8480f7a4f2efd8e362b6c36864becb2f36 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-exporter@sha256:f2249842ba6ef38dca946e8797dd465d8c90a64caa2f27d4140fc0cf02085ba4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-exporter@sha256:96988a6231065c7055465058dc300e318fbcc8db3bd7e4081909c59ef194fa31 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-exporter@sha256:9c5975c0058adc4e2967752b72ba2c7d0f22bfef0deb339e3566a2f2064cd025 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-exporter@sha256:5aca3a9f5e6cf3fd4c8c8b6c8f1f2633fea44a7f5c178d661b93d7f8414e2c2e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-exporter@sha256:d5a9a97f96e40976d81b527d310c81bb96303a96c730799ac76974c91b9a5f46 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-exporter@sha256:545fdfa24427172a5888f4cdd8c36daa779addfc61c9de1028f22de520e2be49 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-exporter@sha256:5ebfc145f8b5d472af78bec923ec60d6950f2333cb0b2b90efc0817a035af330 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-exporter@sha256:cf12f4abb73e0120f2b91d0a4e189a5c5d2ed3d8a5bb0e604e4ec560c67aff0b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-exporter@sha256:4f2d33f9c18dac39606169d5cb6b8b2e90c31a54a270ed245481aa96b38778e2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-exporter@sha256:2152c4b27a2f58570101e8dd3e317805f1d270d9916b6154236fa8a491ad242f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-exporter@sha256:88635ec9c4bbe9903d48be3ba6badbd6f3d963463342f9ca9288fe7426b260d3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-exporter@sha256:f413915e242493094aaa2816b12123939e11bed2e4a0256901f7c980ce28d139 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-exporter@sha256:59bef60f8175078f4fc3b921704a695049cd4824bbcc2a37e61679ce24b47a22 |