dhi.io/harbor-portal
2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev
sha256:d204ed89bfbf7083fe91e023ca50f0606d04977b712ebb90cb748142da6e4f0b
Manifest digest:sha256:08a19a24b904e6c5745583f8e6bd2fe51a28c7d1318519659cb460e4c58a36a0
Size
26.37 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-portal:2.13-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-portal:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-portal@sha256:f20643cf826fe59b317b9aba7ebfc256292abf50f431e6f358bac20d646d67ab |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-portal@sha256:1d976260962429020574f501a5a4c55c907a5c0566ece48058e3bb986796e9e5 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-portal@sha256:8d4c6d312d20fc5078a19bdcdd2a57c1154c28f2e9726530747d7dc65e35f845 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-portal@sha256:37b8cb59a19a8a370436519bc2774d12cac4e7c7cb401a3560f24987166b017a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-portal@sha256:f455e48217eee6b1a1f115c958ff55a8793854fa259814ba9e0322e7e5418a5e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-portal@sha256:2571cf3bc26dbe12f795c30eb11318347c50b74f22be0407bc25944ef926d0d3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-portal@sha256:7cd9c6d66d9f68a260f943f4c38009bd2ffb200a954a72436b91d24d476f2812 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-portal@sha256:275d48b9495910fd5d3815347181a1e68a94e39a740d04e4bee939c83464bd51 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-portal@sha256:3d1a036fa4916463802c6db9132b074f988cbc10acb5dd97b2bda820f900c125 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-portal@sha256:61c500f46a06cd228a8d4ca0babfda5056a370bb37db85fcc93d85e7eb2687fb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-portal@sha256:fe656a9d9e5908b1b4a514d315cda8f0908bec3ba592ddc7ec52a5f0a8b3cddc |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-portal@sha256:94a2adc3a430f6977c1bd9d17df550b399bf2933069eb439acec278a3adec8c9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-portal@sha256:d3ff361e3ffe1ba99e89b0dae17bd9995aa71f6e078a7b839dbe1f59b3d22311 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-portal@sha256:c8d6e6cdb1ae3ae0ed638247263b7f3838f5ce8666f116881fc090ff63e866c4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-portal@sha256:9f440bd532189c74262cf4abdf9029cbc367d543c374db2502aa1d01315e16ba |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-portal@sha256:b74a7d1f86c5b08d2195af86a6dfa972a034366473c46c4ffddcd314a19b0aba |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-portal@sha256:5c6618538d9930b11c072c90a4719418a1e99e1563d6f594165f1efff335e522 |