Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.12.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.4-debian-fips-dev, 2.12.4-debian13-fips-dev, 2.12.4-fips-dev

Index digest:

sha256:f8fb9700ecec8e400ee2d4184747dc9284026fa8f9566d3c57d7c9d3bbe56f86

Manifest digest:

sha256:1c255bfc5cd511d896366db73d7f07531f3fc3b1acec9e8e036fdcdaa8a0bcc1

Size

26.35 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.12-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.12-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:33272911955ae9e54c1626e66a102ac924ed3959d10951c85d65a92790a23c11
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:5c767926f2b510153e97f40d7c110927a4980d7c56819659ceec233964cc4968
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-portal@sha256:42c7c0161a663f8d179b42675ae422f148fc775e59b3e35b0f3b443ba75e9a83
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:b28941fdac5d62f9d347dfe8ae080001b571460c58d7a9dec0a41cf8a5f70d29
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-portal@sha256:adc1e28699ee969706d0b628677b4c0089f3557bcc068c57ebec616dc7164220
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:0a2af0ae3fd1bee11ce0c62650495274c3c27602abfe17325c9cfe322cb1460b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:deac632950cd5ba195a57724263b81de869eb008a7d494603428e12d8cebdc60
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:2171b0e196f30634492a6738ab6fe727f2f74dcfda56702fa17ea7f4b2355977
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:df9cb8488fab8437e842772cbbc6e43119d4be107e584569f39ecd4593b54293
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:3df2dad6fcae55adcb7a5df5189cd53c594c14211bb01e8ddec2a7494788f3c2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:c6c1677e136980ed8a4790f698d6edafa5e22e1575f27be16cf2353bb777db4e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:43c3efa5f71a878fa74a4c96cb59004569b49cd283a85a7b091f7d81d9c739ce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:ba5fcb4835a3a08dad177a81f1dbee3bc2531491db1ce0d26b4ddfda1b487556
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:3c63c6cb1ce083cba5847f065e953da173d1ac7545f8cdc4334690eef3edcee3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:ea2d68d3f8782fb26bd1bfff3944a8430f0cec056b4f875c80a007845efe097c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:85c3211fccd9521be37b17046c273cbd122c1cde8121be245132a9161913562a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:d907be4d166cc06dbdf28511b378cd27c2142655af6198106e53830b2b47d405