Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev

Index digest:

sha256:9e115c5b86d33b5fa4281937dc91840b0c22df29dde136e250e2bb7632fb157d

Manifest digest:

sha256:fd6722cd7e13b0f80405eef16b6052f34c9f1540bb1c66524ece35aeb93ed82c

Size

36.70 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:5e655c08e7d757de40d0bc0af66da2da6fc912073be07724a7f9e7d914a46fbc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:9ccc00191b346baaaeebb84603a0413487bf9a1e43751c0849edfc05229ff7d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:547a68b1e535b508a0b1af56ae3e44c8d0ffe31a2bfdb7628baed9c78a9379fb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:9b7bab97bdc6dfc582a11082cce0831cfd518fd83e42c3caaf0fbd2ad82309d6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:8b779c9fd3ffd6fdf4284b785100db801dbf628bd733608194824bb1d2512476
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:87d81c017b3dbd74e6007d4fad09e2bc7435f8f3fe8618f6542f6308679776ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:347d73dbbc81bc39ed4b7ad385582a09ab3ff72badaf7dd474a25c34b8911260
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:c295c9171cc6d547cfb256d2029d82d03dd858edbafe4320133a76ed0946f46c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:3bdf9adcfa40c3270ab142aa58d6a1959772feb2a0b3bdaf2f3d0b466c5f967e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:3d487891e9277e91eadb77216355e433cd2389410602a82305a69450bc14f5f2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:623671f46dac9d14945f91cd33ec324ae6f6326c6cc20dcb1cf47594bd0f8980
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:48b470c2f185b91c9ea7a0937ed8783fc6cc0b39b35762bd7f30021ef324ce27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:8382f59c50d9b6d0e2f1c12d38e09e248a3b77232b3ea3bc54386f08eafe9e18
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:8b78e2d8928bedbf240a9e3e730a5f805ace44e9be3a59176ba4a9cf5cce6ffa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:5e99470c3b2584dc37c5d550db059976248bb408e381fb78e54a159f35dcd9d9