Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.2-debian-dev, 2.15.2-debian13-dev, 2.15.2-dev

Index digest:

sha256:0a0c95dd29f1d7331fc639ed77caa7f57c07cde7f7d27454d9b6511d9e34403e

Manifest digest:

sha256:cd984623a1b5a5c68c2eb4cc7690a2dd8dc50d0d71d2a4e568fc147719881d13

Size

36.56 MB

Last pushed

56 minutes ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:a8328b7c929d2d4c88b6c57f258d496eed148f563d5504e2c6bf877784ab9fcd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:e0ddc10b9c922e97bb2dc5102cb1d938f596a70e070fbcda23af30a3e2708211
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:b5c55a1ed5590090497d539d74138fadbff740d0d1a6df2c0d21de26d64907d3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:137dc7cf564e3d325a4cc0798a87bf74af41200f34af762d81ec2ad02c00a7f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:78ea771b29f9490f1ef53223f66064a9e11ed1186f8baee713ce1ed5a34970ba
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:2e3165062853d55d0b7b64e2dfbf1c6ff8387d2cbccaba131f8cb42b63776d58
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:887037f620ebdedb6829b8de9bae381e693d86e7c861ba6784960be568a03ad9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:42fbf54fe5a1ba2937514baa56ae8160853b80c0e79b54215b1450aa83c09eae
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:9993de91a3abbda379c40a2f4046e98702836fd0493f73d5320b3bb0111128e3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:33a1d7aba71b8733c45dcd444ed37a565ff52f8f6d15baa68730650dee524247
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:96fdbe8a0796418d317ad337c242e6f3a9355790e533c3915bedc5e15248415e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:3b154dd39c50d04eed7c903712476c8556cbccb631ab5a7cc98e0b7cd373e22f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:622cf37bad94f14170a60d92f3d0b148b316c3edaa6688a4ecbca5dfc25d0170
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:204fba5a65e5806ed2ab9a9d74d3dd1928419a3034a832e6d36eab150bb69098
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:d5e57bc332ce6e92b759a385ce99ede0e4e2a4bb4625673d40b7a61550f4c480