Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev

Index digest:

sha256:9056db75b073918925973826bfc32b3b60465bf13a25f19b22a4390f0ed9742a

Manifest digest:

sha256:10258ee95ffd577657f418cea3607c34d286b0074a2c08d001a74a9f85a667ca

Size

36.68 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:eb02ec139ae841618c14aee357e023528ab9381dd68ce9f08c227ead8996e024
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:528b05c95592abb5964fccb7470cce51a9fd984f5eee3a18021793d8756c0e16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:687edb0df7443d2466c309e236802013e443b08e9539215f2ec97be44e6262c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:604ff2fb7450ec4ff9feb19b470905ef33b939ed5c42a289ae0feb700fcbdb2a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:48c0122228d014bec129ec77f1000504e6b677c3b43cabce2443fef5f0ac7514
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:ec2cd6a1cc6d400f10a7b4454efb56911f5fea01bd2617058df4c468d98eefa8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:8dd380e3ef3f0e57380a5c5e7bb89a29096114b0743c07da00505de208e0afab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:f21d1fee96335e0249715c68059051f7186bb55c86bb3d951628c22262776148
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:a910d46bfa7d140ca8bc1473291e9cbec9a92276029747b3d6621610324c65cc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:cbe22a5818afcfe4b74d4189da8f80b8aa9f37e3bf36c243335317409a512af8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:28d4eb398d84df856b4534e5c9b6d47b73b3abb7bfcc1be03c960acccf9ef138
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:93b99081e1f548a03b37bf7c2a1bcae65e1ff6f2ebf7cb1227359ef9ee74db27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:b7974171180d6362b2d23905d3801c35fd07cccb645fcbf1f8de994e7aabdcd3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:e90787428fde45ef12112d18dee2072b12d143ace05677665f0362bcba5ac109
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:4897733d765e21a1d72013535a925ac55111af3967cfdac75477e69f725ebe66