Sign inSign up
Harbor Registry Control

dhi.io/harbor-registryctl

Harbor Registry Control 2.13.x

CIS
linux/amd64
debian 13
Tags:

2.13, 2.13-debian, 2.13-debian13, 2.13.6, 2.13.6-debian, 2.13.6-debian13

Index digest:

sha256:3908337874f2c43aefb3f63cf80e53eb17d88bd833780c001c5cd17233729d16

Manifest digest:

sha256:20fec47a4facd23af734cc5faad62f5d86bfbcddb5a3b600603841a79392c47e

Size

8.82 MB

Last pushed

19 hours ago

Vulnerabilities

1
1
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registryctl:2.13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registryctl:2.13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registryctl@sha256:ec52ef43b24129fb6b413c4e3677137f063213beefe38f31a680d51ff08df8db
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registryctl@sha256:6f4f296c5e5742161a227e85cf5c7ab29e192c84d387660fd125163e70d0855b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registryctl@sha256:31d2fa6fb4cacc36606ba269252996f0b9a336a3e78f2dde73288519cbf7be67
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registryctl@sha256:469288f06a6a4b9e1e23cf3d69cf64f8515014289c99fc3d8c1000b8edf4f840
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registryctl@sha256:159b3eafc4305b4e182773d91ee969a011a0f43f9a55146db4f4ba0c6243c2e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registryctl@sha256:05dd253fb974c77aa498852b8dcd80dce4eec38a09ee0168f3c6407b91152fb4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registryctl@sha256:811c6b0f3831b512faa5b4042d855df6926b2a2d15d90a3aaf3f5e9f6e0b2354
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registryctl@sha256:ef15eeb306306fb96ca0fb268f4f1210821ccc5f23fd5afb7999f8d99239d355
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registryctl@sha256:7fa85174ec2237c3ec42ca74c7a0d6715e51ca434b4b8eebed1a7f444e580124
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registryctl@sha256:3b0242c1bc89a25bd009b7ddcf86a37c46b75cd00d8cc297d27e0914bdc0350d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registryctl@sha256:227c3cf9b98a2f7324fa5e6aa6c58b5f7cc840810f894467555c60e152d76b0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registryctl@sha256:a0c34720a98fb3e554bb80e5456b4dc0fca50055a1aed7bbb4b89c88d0fa3b7a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registryctl@sha256:2cf7eb0d1caddb22c1056186d0c63a601b7b1e69e18811dc3b5a845cabcd6e78
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registryctl@sha256:c0e46e003def8fcdc584d7c130e8738370ee7bb5c993cd8bc033e6072a62192c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registryctl@sha256:5ba3a80d1bb741ee69a29bb1061c9a942cbe72ee8d780656a1f02a33cdb5d332