dhi.io/harbor-portal
2.12, 2.12-debian, 2.12-debian13, 2.12.4, 2.12.4-debian, 2.12.4-debian13
sha256:3a62471f2aec85009d21408e78d657d2dd3a2dd29a22625c994f3b9518866ad9
Manifest digest:sha256:7c9f690457e3c5844cf13177944cf363163fdf7df2ee7231d6da3d0aafd53665
Size
9.70 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-portal:2.122. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-portal:2.12 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-portal@sha256:572fd46ed653a89501b8360717ddb942cd406c8a2a66c6f32bb69e983edebf55 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-portal@sha256:716d7a3f6014c190117e06655226032ee2536275c8e1b2727e0cbf7be3828a91 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-portal@sha256:ba7dfe485d6d2d44d8de150bbd10380ce39381983257ae6c1280820752e29a74 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-portal@sha256:111b4f91e33ab733900c0ba50e1ef959272b44665148a50e6fa6d4a1fc136480 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-portal@sha256:d04937b3e850bc953e6b0863f8c76212b88c9274f43cdc35b3981043bc7f81e9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-portal@sha256:b8c9a0159c4a83aa4fa5c70ec084a91a0478cbc1f16e6f631947810ff6210bda |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-portal@sha256:9d2044f3e2fd882bc8f8f228eaa31fe5d626351cedb689eec671188b0bb6b068 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-portal@sha256:4b9be11dc1cdc1f508c22e2ece2be23b2d69a7f38d234eda989850f88034b73a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-portal@sha256:440d15c834ce18532f878ae087fa11e57a8bd06a430c7aca19e8d095ef86eb13 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-portal@sha256:97fc00729f5f08b2130b7135c12d3ab74fae9d78fea131e1e669b57cce5d99ed |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-portal@sha256:b96ca8733c709ab1efd6e6c396ef476315f258daadc124f0cb750a9fbb708977 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-portal@sha256:3874dc80cd31a6e3dbd3c9e851d3883c1d70eaf356f7fa5dc85d00988d422137 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-portal@sha256:776daac90509d06df5b6c6e369ba00004803608b691bef67812e97808fcd3e22 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-portal@sha256:5e6bc9f10a18b468d8644c78906f6f14b9ca240242628f256fb391ee31deda1f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-portal@sha256:da943b0f4e62e4acda1c539c3a6bed52a15bc192fab9c10ec18a0e72becf3527 |