dhi.io/harbor-registryctl
2.12-debian-dev, 2.12-debian13-dev, 2.12-dev, 2.12.4-debian-dev, 2.12.4-debian13-dev, 2.12.4-dev
sha256:dcf50f2d8cb4b6d0d2544c3d45281f8377d495416bdf3c6172d38b8122eb1581
Manifest digest:sha256:f59756dcc783900b8e5d3aaec5f33caafaa161dbbb2fa97e07232dc40b6a37f4
Size
38.26 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2.12-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2.12-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:49648edb6295f32f4953a1042ea89f3bce42aee5cc4b112217e92fc3b9cc7915 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:e068b0390b3665fe12a1eb85fb102c82ab2084b413b6368c1aebae442c34c724 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:29a2a8e2ca73b365a2de67e1dfa38e4e466dd3ff24d7f66a53ac442ef7e1d7b4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:ba56cdb7344a8e40a8afabf2018edb882bf453ab1c29eb839e81ab1cec2b7180 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:2c3b002c85cbb5368c0bd1cdeb33baa1063e8c3ff356a7cb0a8ab30a7929e343 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:735955645b2200e72642b089f8d925d323c4d19e7d41d878273a014cb63cc680 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:7926c2d6a5f49eb740f0d836dd0eea1dc9f019e5312a91a2a0999088e9a5f5a5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:8a0ef1ca813fc3df3871db0f6f811e26b08912c028f6e3524b5d77d960fb9dda |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:f080fd4f8b63f75f223b0fce48024c403071b6d4561efe128cbfa39c6024941f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:c25004daf535d0de88dbead0d98ad75e393f667f7ad50bc45a3cd4b0469c22b4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:e06059926bc09ba6d6b1a79e6885fbeeb794f75d360415eea0795271328545f7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:4725d44d4e13bd91e23beef66faa9de78f1f00fe3f9c47be97906daf35dd41b1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:a50c47bf03145f35ee93e69a7258e936bed6dcee2d383bbde507cd05beb28ed0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:734bedae9a4631f35755d3f085f5b0375378029709579a60bf9bbcdbc428b500 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:668acf1517db439ad3dedee9fc75afeafe67716c9ade7cb39b64c32e35410820 |