Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.5-debian-fips-dev, 2.14.5-debian13-fips-dev, 2.14.5-fips-dev

Index digest:

sha256:d9c5df818eabbcfee04344e3f4153a7aa9dce4b803221acb15c39279f1a28383

Manifest digest:

sha256:4adc76000c318c81cf6490e941f7dfcaaf4b3f335532fa9a23e5fd9ae6eef9b2

Size

41.19 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:17cd730ba735bed47318736fa5b4384a01f43087dae6ac7017160458e0ad2d64
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:142e01cdf48e4649266b6dcb2e178cc46f8aeff84acea552b8acb3afe9e88992
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:5958026a53ee7dca152a8fac146b579cb6b36eb0a9142ca532cc9ba126d45e50
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:be99f302fcd08cc751c6b41259a7c438f4eea08f22e197b67904e91587f4c4ae
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:91d18b36dd6deee1346edf37f4a4de866ecc7065a81e0d5089633af439cacff8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:3447b815518ca62b58852adc899869d5388cba62f63439216cb423fdcbe4609c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:86259559e3481f32a60cac5aecf4e1c809035d3f3421de617d771677e4bde474
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:17ab628a26b0666dd87bfafe4201413850bc7bce2b6b38ad346cf800ec37b0df
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:7a50192754cb930274cea82e6d5fe21ec456105c3dc7844260acc54a39785161
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:331f767f07ebbe5a1257e9e010cb04fb92c70517aacfbadbaf2c77087b9460f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:1456d6ac72beb92b80654d1dc07b39ae4969cc26ba3d1640ef5679e6f842b905
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:407ce24bd23bb7e4b207671ba3c9dbf862756b7ee1db11b64eca51cddc5979ce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:11ecbab2e9f3e795e27bfacfdca8edb38adb47a95c8d74acbafdfc06eeacf986
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:8219654c7602a4acd40a93f0d85cd060ea0e3d295c2143e0c0003c2087c91273
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:31b3a12a5b2288b49b75e399857377b780e3d678b775be972f57498b1a6e8898
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:bf52bca4fe82ac790a8d465ed52a908489b8afca3ed260836476005f98a71c48
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:0c2e6e7ee635ac7ee5aa40da1d069a12c79f52de70b880b56058b3b61b4782a9