dhi.io/harbor-db
2.13, 2.13-debian, 2.13-debian13, 2.13.5, 2.13.5-debian, 2.13.5-debian13
sha256:d342f9a73d879f51f735a5a0b37bd06d5a42fe66c6f102e594cb6a8e6c69fed1
Manifest digest:sha256:105ffe8c9619b1e5d617e21411eae553025cbab78774d77d3863084c7056ca3b
Size
62.43 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-db:2.132. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-db:2.13 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-db@sha256:c5bd4cfbe767e5a3f80fd6af1c468e8dbf6b869fecd26c4c965391e978eb40f2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-db@sha256:0d14f4a50f5cb9ce3bd8e5f9de685985bc41213609f0b0a9621a0e74a0a7a456 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-db@sha256:73ee42f537e5d01926d84e3495d9cb48e5a03381acb9357ee9b7fc4ebe38d7cc |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-db@sha256:d869911f0097488f70b9c7dfbf4756fd166bcea731e813c7da59aa6e4a3e1146 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-db@sha256:41468dc69c1f0f1c27347595ab6566b4e145120930ceda6a55050e27010feb45 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-db@sha256:50c0712b3b999b97d19b10517070edb0028e25a0e887bb0d7abe08968af5d453 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-db@sha256:98ce6e0b737a89bd6c0526a4f32d89d88f8f1b626baa2dc4d6faf88754b43d36 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-db@sha256:b99a34555b789d1d7e2563fe0a0560eda2b41e18d07df51f0a047ce4ee11e39f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-db@sha256:377e978e4e2845edbc4d11c78a8141d84cc4322eafa76f3bd4aca3ee07b87150 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-db@sha256:b1afa1277a19bd46a686b4ec8c9bcb7334bbfea63e73ced7abd734da62759ad6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-db@sha256:e94711cb9f796d2e691b418824ebe03ee77b6c3377094bc8b856d464cb86f3ea |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-db@sha256:f60f09cd79b2a3f001f87b97758d11f43a1af65e816e9135ad70d79975b3cfa6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-db@sha256:3073bd784a89e5ac51b2dfc8b9e7233de8890b45e6c60764634e1bcc728fe887 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-db@sha256:f63bdf71dbfbc44dd0dbd4d7ba62cc0352055e822dd47f7ab47bfcf05c255feb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-db@sha256:70c9443a9ac484e009adc0794c5b65b627aacbd4f4a80b47495a28debdc5b300 |