Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.6-debian-fips-dev, 2.13.6-debian13-fips-dev, 2.13.6-fips-dev

Index digest:

sha256:73cb6556df47171be5cc95519ee8218c837a4b16e9543674e9ad091d09ebd025

Manifest digest:

sha256:237eb5b6375e68641c1c2562360451b4b58336a4cd33cae2ca2b2bee044710e8

Size

37.46 MB

Last pushed

14 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:786e53993cf5e89cfc7ba70027e6cebbdcc9a755de7c265b9cddee616a917e00
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:588014f6c1e75d52300241e07a792e024ebd457adb210fa532dd16dcfc80bdee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:9c39580fe3fa6b57930ca42915578fa8651f4dd329f5988d510573cf3cb24e18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:6a1d39c88a5663015a9d9c845baba537e58a45ac7b6d2049f5d0ac18ac26919b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:1d948cbaea7c0e2c47e7360349d9a45886d309e95ff5a9fcb6fe602da5985480
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:f3be7518bf4aa095c4449f8ba7376e194d12ab59d378f50eac92221e21d26db4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:3e210d00e3a3328ce17d2cdc79711a5cbec0a779448e6ca39084cc5f0480e8ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:ff0eb7443fe5f4297b860e2023ac50df4aa5ba09a00e0805d5d073c247206c3a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:af601b081d27df00a55e9d076c10f0bb4553d2a9e10614c0455783253a3d1364
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:9029bdab8ab0a8140b9ac043e246e84a3978c9fbef1dbfd40dcb88c04bd5ecc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:70be157ad672ef665c4d82ea21bb0e4e95e9d099678ea55f40ec9a8c86aab7c1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:d9843d68201d228902e2dccfae95c71b61d08d32eb9ff670722e25e1e0d84825
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:51ae201eca966f3507f973566574dc5b26abb27abd8ac51b10a0ea90f212b911
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:0fbff71e0f7fbc873efb74a89454a80e330458f67fb4e5390150c97d9f20aee5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:246dfbf6d79d777f671271d0ec9cb12a31451945a8a4f404201f16eae9f668e8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:5ec81c8aa22fc5d9d25baf28642704c1f191219f9f08e81590ecc593c2577dc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:4cd1c6e5291df990711725c669e1f00212d683a8a92375d157eecb41868025fe