Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev

Index digest:

sha256:bd84a938e895f3a92f4a2e8c31191c1e6f3df4ebec2556520a7600cda9f5fe57

Manifest digest:

sha256:bc7d92de511ae3ea10b45b006502b7e65ebfe3e0b4dbc64059549bd5ae1baf79

Size

36.70 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:c67a7abc6637ea1ef2253fc6d8fd053ceb059a60221eb33f3094d88a1925c430
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:1efc68d933a392a4b0a300505bfdcf54afd27301b4cdaca479f1b80e3e76a1ad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:e98ea63cd10b44984ee9b97539dedf99b0e2d45cbb35c058cff72c2fa3533ebc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:3db005c06ea04e043b6f738473f6da4a2c4657b4600357da67faed32ea8023ed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:cb6f47b6206300e2a2e191a0bbc4173824b628927a7b02750c543b23da9a2ce1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:e3a77768aaf5cca16ba712f361070143fa95d17608a7e5953b7e6cde4d4af688
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:a7fe5f9ab6bd9b0f57659a6701a9456df41915f4e0dd3af0b7bd9f774ad283ea
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:4a80f10bdede85bec455b87cf7639f0efa28205eb958aa04566de3eea87f0d8a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:6266630d3f4737e6c4ff08c4513470635b72b14d03668efd6f0f185f7e56c47f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:0714c1cc08c3db1f4961f40eb1e087867b7e13b3dfa9a5c760a887206835ca5f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:9800195bef141fd1711a4cf745e95ed35b768414d7158c68139f41539eafa297
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:c7fd298f6b12affbc956588198397a5a49ae758e3254c8ca1602a6ad013e7fca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:08bd881c166105a64e3387fde825cef25caa28f172fd910c8432cb2d56c99970
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:6fd0d6ce63d170d191ffb9f57e175c4745cfd7ec1f3392ebfc8626ed9344edbc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:cacd9285afa99a964e94a68478c583659c045ad18f8e9eaa93f36ddcf81c22ad