Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev

Index digest:

sha256:4a6c35f9b8221daadb2b3c60341c72a249c26241c9804a51a9a594b685787b9f

Manifest digest:

sha256:d2e558281505aad225ed74173aba488c6254fb19ce8c9a62a46dfc003441d096

Size

26.37 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:69dbebdb220937ac014d480822f4bcac5d5f422ae3456a25b42605bba6a36590
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:90f74ca649f4cf23f518bed111fcd2ce5ef86b9112e5b135d52bb11169710240
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-portal@sha256:a5c54fb12953fc1ff0fbb26c71aa25dab38b70e6ec14bebc48cf765cdffec3ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:1d0be3011535bdc9b26fc5bfc4542b9f6f17b28f306f4f716b9a19c565f0fea8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-portal@sha256:420ea4b32a60fe26c835b6707220f0fd44eafe0089e1f04f8ad0d5f4c76d8a6d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:5fbcaf7d609f1b70e50563a04392a89361954fa1ebf9518abedfac04936bb3d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:ce49ee999c9c11268b20225964e7ba5c2c0270f1537d8dd4a1af790168d41040
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:517cd2361b521b5c33ad93199f944833fb7a10494969a7693f171dd9e1afc534
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:4aec9d040ad79e0ea6f1bf218275824e3fa21c2160695e586bd41abdcfeb3734
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:acfdb9a5b2bd9f2bf523b97be259026b35447851f189765884a130bdefc69994
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:1a0e8d4941dbadd2137a38f8bd9ddf083194b9ddab197690998b6fd40762eabf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:ca97feba02fabc016efe9bad237850bf28d8fa41d9f0b3264907c7cc76792df8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:089fd8d5ffb5fec097b239c12e8276d59289be2759cf6bb08a87e02f107876b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:2cf74bca204ad2aca16c219840460a293d8a74aca88e3f4b7d02f6d1c6207b32
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:a8a05f9927471e80079e32cea97121cf957d7960e5d6c6c1ad7fbd40bd328a5b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:2a94ad9c3d687d46c866f286905d83c7255c2f1cae2084f17fac4a0bea9c35ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:cb95f45272c3f85bd3f0a49a8452b9d80b44bda7daa4453ec9d16212bd7dc312