Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.14-debian-dev, 2.14-debian13-dev, 2.14-dev, 2.14.4-debian-dev, 2.14.4-debian13-dev, 2.14.4-dev

Index digest:

sha256:dea173954c23498234d55bfb3ed4cbb3843abc54d128e8ec867ec70e1592c7a4

Manifest digest:

sha256:e2a6492a2391a2e700892b9137fdd8cf04e3de9792606df4d8d4369023739dc4

Size

25.63 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:7bdec256d05d8bf7a932779323e3fbc2033da5909570093df64ff9e3a921a455
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:73c8580fa84243c00ccb3233c911a35dc348ab9490472e4fdc07d01aaa149bc6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:9aa6ab5fc7d9f0b28d3127dea1d9ea008d8057ffc8e2e6c6b4d8a129db0ea52f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:c2f2f8f7946355b372cf7a99724da84ddc10548b7720be41815dbea75b7d5fc5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:9dab3bf2c70541d03193f544da1aa1342a1c67755d8373c3c8c8bc7a4a0aeac8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:732f9c4260e65b453c3fd1e7fef8312eb4f25199a9efbea946d7258254342df2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:7da96852cb17f0f681796a88dfcfcb3a2f5a35ba5ade76658eadf53c2efd352f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:761631b0fe16ad338db95064e000c931ce58fedd96ee68ec2b35d26ada303939
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:87bc88ee81d8cde432e40e4dc3dde01b5392d52ca1a88b0f3bda9e1084ef0ade
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:6b3bf6c1f12a02d96dd3442df3f159990ebcd5b3c71ebfb1c1db37ddc0ddab5f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:9dddff6bc5e0bb5b53bb98998d664217243dcc19940783fa52bc5cc1eddcbac9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:37a41d89c4a2402b0e60cbfdd317a2b66aeba23ff4d5bacc13c68c55719b16e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:984a926b0ea18e80cb5f372260bede18217523525db635b08033b52dc8726e19
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:1804e2d4605ade6d7dbaf18238c43dfbe08dde68a913df7530ac2696a975e076
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:6f3ec9bcb4021ceac7e763f1646939c9a4dd7e2e88aff441eecaa3123463a256