Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.2-debian-dev, 2.15.2-debian13-dev, 2.15.2-dev

Index digest:

sha256:a406855f42c13cd876abe7e4c01ed288122c73696c89030fc02e371dde8d6de9

Manifest digest:

sha256:8a1f9b6f2b6e176c1b21eb049602e512e5d68b75bc4b2da831d051eebdd6ad7c

Size

36.56 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:d23d9492797c9a9d2ee147e2ab943b4f66b6674fe9ee3aa7c241814c505e48d6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:88a357d0440577668dd5e8875af97ac2d6ca92ba327abded1abf3d1c061b58d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:23b0df43b827759826ac178462051636a3dc3080f785aab497e0f68028300bf8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:553ef3f79267da69ca86621c5ad171305e5c4b13a14aa3b6a9fef76789da31f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:dc2c1653829a0abae6548b2e16ff7b357c1fe5b8bbf6671c3d1fc97e54b3e1e3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:90c18bb601f0134219854dd5291eea54120b8b9593b146cf55fdb22aaceeb8b4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:37931e38a1d360f6c73a7c7aaa05b10e0fcf47e854bc197f15d820ed3af54c2b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:b49607cf4df1fd615af0fd0a81bab91f26b1b2d438f2a4d5babd9b3c6240194d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:32a9d1a6769d7aa6af6c0da282bc1aafc4d21b1bcc4f91c0b81c4e8d0d3f8b2c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:473b8260bafdf746dd188e001f0060c354d3960daa658c092bd18f9e3baf13da
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:9429e5a5cc6e4ebc4ef453edba9022724c06826d5db009a4151a0596c15b63d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:8d70e4bff3b97d44fabf801b48bf3486cfe2b3480249de1fd9f3bddb2f70d73a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:9e9e31bf9cf996422ddf773408dfc7dc455e6870409cfb5ff398bd3daf4b1189
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:439e2f39b1102a167bdb0cd6284dfd42bcca20177b8109246480bf42b99d8fb6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:9e8f2a33f922c5546e2ce93646e41ee57ea15ca843febe7a1989f36b69abd662