Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev

Index digest:

sha256:a11e9a4de6fe1b4f00a00df491bb4378c0ebf4e2ff759c16bf3d312824a2db21

Manifest digest:

sha256:1e7938d5a20bd3123abb8dcfd4e46d38669945051757686a0c4f9e4f7b8dbc69

Size

40.40 MB

Last pushed

13 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:453d12386d33854a88e285d6b28b648260ea4aa1d12b863e1025852499aa2f4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:8ac3fbe9cdd2f2d2237f1b7e926b7d7bf056b89c8a9b78037b12129faac8d020
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:34d1d2db336a236351660cfd02326a84a4563a872849ce7d6c44442ee14bc4c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:9c65bd6040272b12c735d8e31e725c1b02e4a2dba3c891d2e19386447888d60d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:d91dd00fce8e674c0a010162216972f76be16dab2e81afea68ebceec3690deea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:051932e263f14c6ec9d2163533830901bac75684f9e0c2e5c5bd287e82197d90
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:41d5fd092504ddcdaaa0d6ec6e241e536440cc1dc1d8900ccdcab0f53a61ead6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:bd5dc26b1aa3dffcb6acda35f54eb7cb1513ab8bf45d0193395e24d2ccb7ae0f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:e56b6034ca8de444a3f8ac78a0e103fd6d7eb56bf823463b4b4fca23c5cf4751
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:38fffce8388ac9c04c59b9530673e0e71274c816bcdfe50f8565a899916f388d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:6b9c214060092a407dc8c07726e21de7625de9ba66128df20b808518701c3c2a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:f56a47ef4650a828d561d5615201a0555b0d9a446c2a0ddcc2033a22dd8f581c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:33f2ff8184ab31312b86fae490b1c7b8683c5ef314571079524dec6f8f6724bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:b441d28843861a91675dd8e41355e30b69359f50fe759229f73959ce9ad76eca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:e8a0da609e20573e40cc834700e0d48986d3179346c119ce6ae96d4d0c909637