Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev

Index digest:

sha256:9df3df2d7ab52ad72aeca8ca70e2e2fc64aa89e8bf00f1c04df6e93dd70cd17e

Manifest digest:

sha256:624620ef4301b3fe1f1ca487ea29c3b5bd57c606599161fc9b67a4e4492d22ec

Size

40.40 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:fbb576ef9b361ed40bf4944a09cb7b8e83b154fca66fa0ce8223ca4b1c8b86e7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:d4cd34b334780a33a466e23a769bcfb877dd80b5beb2b1b2110ea08b54cee366
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:2975db27d27f2d6a4f02b4b41b0d3543af3cf1e889a777dee13d84c439e747a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:a3f063c01a99ec919a3384785b629c6e8740484d2b8cf2f0667b0c35066202e2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:84f70f43eb47b3ca3bd31261074b4324219767ea7267068a070b73f0bd5687fd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:12b94ff416b82284c190d6f541c3b98e6b1d725b3090b2b758e298e8a21b947b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:48918c74abf13e4cfc0b0b61c5d61d0b51b74166802e6f758c83ff5db07e61a2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:a9a56577a54d0b09f808e72cf5e39d4d329cb2ec58ba769b41f172aafdb4b8c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:bffe2372084d250f957145340f2dd989a46c542693f63f1787fb74d8328d3816
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:4b92f78123def87e3de326050fb12e01a876eb19cc3cd8429f0bdd033b096afb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:e33c74f0350fbaec31fd6874467221aae41e263c99cac37bed8bb7f00bd020c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:cad76c1a0e7f9f865926d24b4f9f190a5af8620c9c654325d0cdc6c5e0dea2d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:a3c0df41f981c5c28a44e88b2f313334a6fc2bc5f05c55e33d3f6c8652a2d86d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:85215c49156cf094892117ecdfd18014686a25346fb0687a4ca6f6fba838c1c2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:44c13c12aead40c48388e5e9cfe46c0a67d5165af918ed5070c929bebc1e72f4