Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.3-debian-fips-dev, 2.15.3-debian13-fips-dev, 2.15.3-fips-dev

Index digest:

sha256:4e056fb4c95167476a6397841f41fcd433b58b832917ea819abd240b87c71a3d

Manifest digest:

sha256:0690de6e71773e355614404b95ed1a0285753aaef36331d3de9cfe3e2c1722aa

Size

37.46 MB

Last pushed

11 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:57c2ef291adfac5fedbdc3b8f3fe0a0c8649bb0465e58f505b11b922d5e16cea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:5c8e7e57c3f47960be9d93e717a80d110018f4ecc12f9b9cd4f55fa54f058f2b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-registry@sha256:adb8ff4aeb5955baa8ae4381208f1a16da6d80c2920143b39051139b821cca77
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:07b6cd35c797a352e09f74338e96bf6379684975b3b3d494f1f7182ce13bd056
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-registry@sha256:8d99503ceca9402594d0214a862c6747e2ad40bdf98f21cfe71e1fe8488f93cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:5ed3b803df8122d70bd9ede35186c783d3ff5f51ce60f6b2ecfb68abfff4d048
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:b48f44b63fe63b73e8ee807863b9f9c09a85139ee02634cf19226d3038084b10
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:1e7ffbb71f85780666e942db3fa36726258e7e2d2f160935e70896aa6d1ee5ba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:43886ad73a2ebd25d0aac943f40a7bee23a03693cf2de4a7a3a394615cde9b4a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:17b7c3cd2c18250ee8d6dcaf7d921a2cf1603056a86bc4bb9ff781a2a9f5dbf5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:bddcf3e4dfa237f3b43b1da66b5a12d06ac3bff84640551583ea5d553d5e3191
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:abff432aff4494c3481f36d841a87e267e01535b128566f4467a310cc09d39a5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:19655f043378cc1379f3093611f09b0dbaac8665ab8fb184a67db7dee95e3f52
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:123846a81b001839145d4813e650a0d1b25ee86bfa901c50d583e5a5cd42fcf4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:03fb0b79bfc947b6c63cf108edd58c48588e76e5dcf89fdd0dfed217416a6c85
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:07e5fa9a9f898766916911e493eb849f98f92c2c20650afe30deb91d4c368497
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:ee451222564611d5b6f61a38ef60892ec9c4e205e52c4df00b13562c91f2a035