Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.3-debian-dev, 2.15.3-debian13-dev, 2.15.3-dev

Index digest:

sha256:fd80c16dccca2230884ffff02df7133c54e9d11b2e4a5cc4a6f31b3107cdfd56

Manifest digest:

sha256:55d2ae8320768e021fa749b26331cc81d50729db837a19a161865219929f1349

Size

36.68 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:1d7afbe835976a962abc7a4ea18751b9dff5d97f9e43e0e5620c26c7c8830540
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:1e842c70ba9c78fc29441034344bd4d6d88a030b1b605d4ad803b8198e0f801c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:5f9d61a6bd5ebf99da62190d6be22929bed31261f322e934f16585cedd671cc4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:6e5cfed10d4ab836e83a4f39e02b578393bb1ce7daac1cc8b5cdc5df3aedd301
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:2ca2f219af086e6f862ef73e7a17e07d14fc5905ec72cdf64a1b8fd24787eaa7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:8cf2ac98b0d8d2b82239e49315ec12b4c53f4b2122015e84b8fd35091870edd9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:1317b57e4a2e9f1d4d7c285854ba5dcdc8c71b32088a12b56b5f875338955873
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:56971e2431b32f9654ea492fc6447be0cb95dd3e3717cc3c2c4611236384ef01
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:033830f9991e770d339af065a91aaed7d4e320d7a56546785b1261d7a1580642
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:9ef5f771be26dd8f1467027c81e99a2e05ff372c0afe43064ac5810f8484e327
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:9af31b0ddf41b3f5ee518765a05e767263923ef77fc878a722a10b42f3a67dec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:a4791a0884c922d3ad2f14d92c5cfad4726f8d53bbbc75358cbc2597d8fe9034
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:abc94a566c9b440fc0df0ce1ff0bec937ea73faaa43223b46d283317c41e6868
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:79cf4d48c185250c180aab74cc0072b4b558178f10339b90e4fa32539a7ac370
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:423b29da730ea3ad74d3622b13d33148c85f5d73b79e841b2bbdf29ced599fc1