Sign inSign up
Harbor Exporter

dhi.io/harbor-exporter

Harbor Exporter 2.14.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips-dev, 2.14-debian13-fips-dev, 2.14-fips-dev, 2.14.4-debian-fips-dev, 2.14.4-debian13-fips-dev, 2.14.4-fips-dev

Index digest:

sha256:113d83bb10f58b51f2a68fbb6e845890baceff791c7dba36b59e431ec1f7f0be

Manifest digest:

sha256:70bfab77ec99aa6d10403b2ced4828cf5901ec2dea099f47ed5d1ad350c26a64

Size

41.15 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-exporter:2.14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-exporter:2.14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-exporter@sha256:443e75d7747b5e1444d386c8c9b48f8b56861ca18d6067af682d7d78a82d888e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-exporter@sha256:d01177ae9223c5949b82404809cad2e845e0b6306857427f73ed69c628564f84
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-exporter@sha256:fa508b9901e964eee4abf1fa5d56f6d58e658a6a882f5e82d29a65cc7b0f449d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-exporter@sha256:0989dd2dc8cf4b053cfe71aad24d58c0d66839c5f242b0c6145ac83e14174afc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-exporter@sha256:a26a92c0bfec53b5bcb1b7353859e44cad112b96e0c213040e76cf2278c10872
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-exporter@sha256:39b6a5c1db6f65d3f382bb7671c44c9b269dfad297f09396cdc58f84202d8e94
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-exporter@sha256:bbe851430c39c84371a7e92264c899ee4a0cc99610d787d980a55d4794625673
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-exporter@sha256:d85a0719a198944ed04a7fbfc454c44c7dc7e1354afcf1ab47b7ba3246a58168
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-exporter@sha256:b9e93713a66930e14d0af74b3250d87015fc8bc5c8503c64c504ad3780e36ee0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-exporter@sha256:5fb00cae8745afd0c79eb65003bd06cdab91ea7b15aedb6b17ae2f3bcd353125
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-exporter@sha256:010f5b0cffa366bcc3a486b02973e7353e3afd058d93f5cee6d02b26ff6e21e5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-exporter@sha256:adbcdd18529cc1928a5536739d8af079f9a56ec65c1d935829b1f09061ac67e9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-exporter@sha256:a683956c557d0f99bcc471de4eb6243eecd390a12c6490c85b71d0bbdf89f3a9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-exporter@sha256:5ffc4afa15194bddc65abe80e11696bec828069caf5287dcbf1f9ae5916bd3ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-exporter@sha256:ddbe9a79960fbc3b87055101625c23b1badd210c53e5ee7370b93890e0b650c2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-exporter@sha256:12791b57e4c34d98ded372d21caee96a94d75d2a101a7cc975ef3ca520c6b1b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-exporter@sha256:5239cbdd3d51d38e5b6585519409fbbdf4a3e7b44707e57b453fe4d5bb709056