Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.3-debian-fips-dev, 2.15.3-debian13-fips-dev, 2.15.3-fips-dev

Index digest:

sha256:011d941ff789c44573f7ccbe3f373feb4defb650ac34d46d49f4694da5a47ad9

Manifest digest:

sha256:9a48e48eb403e00247dc4f7f131a7a677de8ddbdcbae3ab5f42af0d27a8e239a

Size

43.27 MB

Last pushed

15 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:ef3714a55f69e037baea8d8fec348aa42e6cf75bdd1b023b7786bbd62013b923
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:47da9b2a04a3d433d9a03b736c11a2786cbdbff9705d75cc3202a2d70ad23970
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:8278a041d54df1a546b4e281dbe2a316672e88f70c6444c5fbf356e0e44dd546
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:b73544dfe2cdbd1ffe8575b45941fe7bdebe3299710d012b1288ffb32438e226
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:c6ad58a5da0644630dcbb13e6e86989d7a30451c2062a8dbab97d5b95998227f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:a7c6288f504ad549fb5f1938217d8d7812c0296736ece748c96b05b446d72dfd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:f448068dd2bd6f06a83e5253fea435882207b17eca816ffbcb7f02b67bb2465b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:79950b8cc09cb8909fae05b8d753563cb2b43376ec260183a8b26c73e01cf1fd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:ec3ed36a3af7fa17ec6bcf5ea123c7a3a2ab56c9e7db881d95f75c19a1d0c806
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:3c243b29e6c243ce4b8b86dba300ecb4757433d6169e6462329490798b4ae72a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:fdfb159a11d06291fea8779321bc015f13226525c96606fcf70b147eb69a201c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:12711f40122adea7e169956dfd9006e6fadfca5cfab857bcbe98d026f1c4044a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:fbe822155dfa4ce402e0ed236fd487fed02d16ae3dfc94a62824ff6a90d482a7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:a1b4187df12febc6f62234cc797690c5a63042db0402605b085f6630b317558a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:89f7dee1a19f2a40bda89d3db6cbcaff720b398e68f7018e3f8b07cc66fff3ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:69e57329e372af2b42909b1c5437b1d7377e663a222dd72244758c269fe06f30
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:dadadd4614f8fb373d5a1c1a592f66f41eac29ff4b533b818673ffbb437546b6