Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.13.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips, 2.13-debian13-fips, 2.13-fips, 2.13.6-debian-fips, 2.13.6-debian13-fips, 2.13.6-fips

Index digest:

sha256:8647fc10e0d31179220c1a58d3964768c47530c02428b4e40624d68a16a67692

Manifest digest:

sha256:c2365acc59006a390eebc948cfefd28e63aa285a18cd4e6639933db5be3b6d40

Size

17.60 MB

Last pushed

7 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.13-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:4a17a385db918dc5fcd144d9e9317ffbcb8ffe61890a0b10764e4f3d1a436d80
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:47cabf0fdcc01f0946f3001c4083dc4c5f1a87f112cc9d3421159ce6f8209a51
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:dae82c5415186e0df49f831e3a0a173cc6c30ba97a8b606aa57ca291b16a2348
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:dd5a4695726cdc4648c300d41ca33f8480f7a4f2efd8e362b6c36864becb2f36
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:f2249842ba6ef38dca946e8797dd465d8c90a64caa2f27d4140fc0cf02085ba4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:96988a6231065c7055465058dc300e318fbcc8db3bd7e4081909c59ef194fa31
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:9c5975c0058adc4e2967752b72ba2c7d0f22bfef0deb339e3566a2f2064cd025
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:5aca3a9f5e6cf3fd4c8c8b6c8f1f2633fea44a7f5c178d661b93d7f8414e2c2e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:d5a9a97f96e40976d81b527d310c81bb96303a96c730799ac76974c91b9a5f46
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:545fdfa24427172a5888f4cdd8c36daa779addfc61c9de1028f22de520e2be49
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:5ebfc145f8b5d472af78bec923ec60d6950f2333cb0b2b90efc0817a035af330
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:cf12f4abb73e0120f2b91d0a4e189a5c5d2ed3d8a5bb0e604e4ec560c67aff0b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:4f2d33f9c18dac39606169d5cb6b8b2e90c31a54a270ed245481aa96b38778e2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:2152c4b27a2f58570101e8dd3e317805f1d270d9916b6154236fa8a491ad242f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:88635ec9c4bbe9903d48be3ba6badbd6f3d963463342f9ca9288fe7426b260d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:f413915e242493094aaa2816b12123939e11bed2e4a0256901f7c980ce28d139
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:59bef60f8175078f4fc3b921704a695049cd4824bbcc2a37e61679ce24b47a22