Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.5-debian-dev, 2.14.5-debian13-dev, 2.14.5-dev

Index digest:

sha256:65fa1e14b2185b651e2c53dc7167a6351fe26cf5562a388d1637cc1bccf0ecc3

Manifest digest:

sha256:38935dd131ee0db2acfb76c2a87f9f189834a78b0818863a957a008b17b28167

Size

36.68 MB

Last pushed

18 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:4f7651ef569a5a82194aaa6ddd70ac6b7a718b0c0591bd531203b47160265d4d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:5c2db4ca357b546f1198d91b986c0b0cde8f019c5ff503be692cba8e5eb4eefc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:b2305e4d6544cb46ed9e84eb4449d9c27a2bfaebf8767e862cf5dba5bfa242c6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:91c3a3de3b68d0cb54c38240d44ad02e0dc084093b0ff29853637973d0adfe4c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:b51c84c0b3fac65e17899709a691c372a1677ac3185bdc95f0f988bf904b359f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:0d939e9d601e38130fedb585af2c59530a21f416062d30e1a25d34defcec5645
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:68a9b1354f58e6d3428a6a0f3e2214191da651a338398c7d3d532b39ee2805f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:7c44e83868672beb03188dd49af141353ad38959bd020391a6b2bf5b08f66710
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:316679d35e3b7dbe4de7d4ecb0ec5cb49f2b1ef68f7f404734a01d1e5573aa56
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:27ebfa7561fd196b365a388d2cda9caec0d38477575b9660b0b2992cd409041c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:9c46a13e8e8b07905d2a7d1ee4d3c797a3294f21fab83310a4b5602774d593f0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:792a538022a0328b0556009b839204e64d43bfba88c6a2a37ac15fe29198ade4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:4a1778f2c3e7013aa8f297504874171fcaba85bcbba2a10f399b617f7cc559d7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:df237967ef1bc558d5db6026c92473ef1389d8dfc7ab11c8a0810f68d116e8ec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:3d1af24c859f447cc8e124fe2a51322eed6fe95aee4ca8fb065aff1b22917e45