Sign inSign up
Harbor Portal

dhi.io/harbor-portal

Harbor Portal 2.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.2-debian-dev, 2.15.2-debian13-dev, 2.15.2-dev

Index digest:

sha256:13b0294f4ca38424e99c57da5e042a1d8743fb0fe7b032744d9b5cfd2a003814

Manifest digest:

sha256:11658cb1f711539832ae72b77fd0830c31a58d6179320575fa9423a0cc1e7066

Size

25.86 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-portal:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-portal:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-portal@sha256:05870cf4c03fa0ee933f29606f0d0079c00d8e064c79fb958088e15eaac6e0d2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-portal@sha256:b0bcaa30a3ceb605aa34f94fc5f86e22f7b8ccda2e53434a13dba5529189b9f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-portal@sha256:b751fc18e82213564333f7ec9c1521a973c51f5dd92f91bae05118b1bac414fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-portal@sha256:6db44510e3bef1a216e370ca385fb986b5b74bdc1bf10b68939916c2f1cde441
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-portal@sha256:1052f2b7a98f7f0dfe0fcb238c04abdcb222b51a56a22c043d30cc858808af6e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-portal@sha256:d867e3d33835fac2b269f33d240e95f68a48dbd9f5fb41f9625f7ff964a5191b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-portal@sha256:46ed7dca2295fc04396b450038d8245cebc935cb682985007bc3dace4330bd45
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-portal@sha256:b022a2d712a8dff94d2533f43cb7d29265bcad1a322155a052ff5584750f0edc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-portal@sha256:ca4026b84f493925bf4f032b8ef6124fbf19eaa207f94abd8cff0d3d9f23a09c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-portal@sha256:69890ea2a2a086843c12b87e6b543a168fd43b84bd7cf02eec6a438a27090b1f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-portal@sha256:d66b5945e5b77e2078ffa082456c47b06b978c8e81e8ca21fec32fb8f7a7a59e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-portal@sha256:457260f00a6b7daac94c8731f36cf2e7c621adb4c32d494f38497608e7791559
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-portal@sha256:953bbbf0fc4aa868d452650f0045dae21fd1defd30e792d1e1808203f008d4e0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-portal@sha256:34950e62b110d373dea335cd88d1245d576be9aa377813fb58b4e460606c1143
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-portal@sha256:af10c4b5be3e706688839bb8d36b7df306ceece05e16c46d5607b0f533c5e141