Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.13.x

CIS
linux/amd64
debian 13
Tags:

2.13, 2.13-debian, 2.13-debian13, 2.13.6, 2.13.6-debian, 2.13.6-debian13

Index digest:

sha256:ed8474e9b2af3b7df13c69f4c50f9cee0c4c8d44b9246298222825ac10a6b644

Manifest digest:

sha256:9d7a0a48f4cee4378fb7e8cd3d29adf476a0da47aeaa0084e3940aba90712621

Size

9.42 MB

Last pushed

23 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:29ce7a431aa66e78dfcfec49ad281a7d77d8b1fccb3d4ac799e92c5285640cba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:402e7cb2aafa543b82a2ee1f30206d897e0bd31b5efe54fac120a6322c3f7478
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:c0625a5cd93fddde8d64364bc1bf3dc31bfcfe6006f36377227587605464d645
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:f50dc9b00ecce1a92596b0f2e35caa6b3daca3bf597b673e433e15b76cc9e598
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:d1e3843d22dffc91e82cd92d87ce7744049be68fbc13803f35f085764540ba70
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:c0537dac5038fdfb7b721915e1c111c081cff7250db88e3d9da72944c6e118b5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:4158c4d551efd0df346fb873bb8d16fac100bc95d92fb9b719e6e76fbc33f36e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:fe5b5819526102cf59ba2510e6d5d72ec8c1343318f90e55df9b9763e8f76f1d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:35e91d1fc235a31614c2057ffa4d0172b9c22608b5b6400fc394332fca05a665
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:4e4731c132e4c5772f0de246f07aa34735a62e27d6b2161767d8809c13d6f9c5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:5e8cdac63f38a718ceb94c0fdaa07064ca9e31a9cce912c93cb9279ae2de93db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:64698d60a52e0d96c330c13742e7ade14b4dd7a5ac79a2a2300a33bbf3c24189
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:b8192388f0eeda511e7330955247edec39953d822eef39d018a10cfe754a8391
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:9fe1f8d7be6a1a95220b1c98fa652c2092db70d0c6486f16accdfc0d13eb5a65
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:7abc224d154698b53f3db7b6383b0047b66eb430f89badee48e25d530ec56806