Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.14.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.14-debian-fips, 2.14-debian13-fips, 2.14-fips, 2.14.4-debian-fips, 2.14.4-debian13-fips, 2.14.4-fips

Index digest:

sha256:eb6498507300b0c0b05ac6d233477b2afaa64ab2262e40f0f32a3b1712cd4e9b

Manifest digest:

sha256:96d4d42a900ae25ec058cd87872cc8b82cc98fd13c998844213333b5271bf9ad

Size

11.91 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2.14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2.14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:ceecefedaae7d6ef31590103876270ff167b198d2bedf35edf5a0d19c33c04b4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:0a2b5fbb43942c2056ac24cfd99be16f12ac2f9ac148e6cc054e329759dbf525
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/harbor-portal@sha256:3e54c8b9f3454f94ec8871690a12773bcefcefa9116f8edae045d20cd5e99407
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:43632afd8133142291b143c18b4938ef3c5ea88b18dc3f0cb803a6b3da010599
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/harbor-portal@sha256:fd4cebff20987bfce504c5098846c12504aeb99ede83c5c4ddcf286e8dd45d29
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:38b450101913c904f2999949de2cbb588b26a7a405c58419d978c52adcc031e8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:091835d16edd57fc64913ff4ac6ec21d19f6ed5c931cb5ee7ccf17d7cd67c9b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:0dd0876956817ac074c48b8ac9d9fa2929dbad2465874ddc0507a6927ae588c0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:9b4f254393ad9b67a553affc681b1165176c15d137bbef788dae8adb86ddcca0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:453cad051370f972722f9896119ec83d1c2e70ecfab644341563e47e804acd7d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:aea0ab6e6ae9ee7bb1ea140c3e2389baf527bcbf1d968ee0883d05bea466944f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:524be4522dbc7ede0d690d821ddd4ead4b2899a0607637d90b69a2ff2a7c0b0b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:07244c6035b579f9bd326f75e7ec25c22f9b901998ec6095f903222469804234
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:80e14598fff992daac85c2f34efb88c673c2318edff6c99d1d53c5bb2f1c6618
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:2f5623191df4bd5d7a1496a1db02eb4c06fe41155845033efb3ffea1b23de36e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:654deb183290c19022873f8ee995f3fa41e2b4214d9a2f5c8ba9becb3c2305e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:c6293e14b65c44da4aa714c320a77f76fda6b416ec68e1ad9afa2e4b04df62b8