dhi.io/harbor-portal
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.2-debian-fips-dev, 2.15.2-debian13-fips-dev, 2.15.2-fips-dev
sha256:56abf9915b36e6de5b75114a19b669d50cb2e746a2afc892d204ac6050d1bf60
Manifest digest:sha256:56812207d4e1e68dd8735eb46125518ad1f54cf8403e54f864dc0a1816dc8e1d
Size
26.62 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-portal:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-portal:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-portal@sha256:4ccac10c7c1dfc7871e79daa0e6888f7ee6a153289c2756afddfd170cb3fddaf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-portal@sha256:40702a4a1c118601f1d20318c3ad2462cc58631fdac99dd3994381ef546e2aaf |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-portal@sha256:82ace25f0551f53456b236d595c4ceaca0d9223cc0b0d9e10e91756ae6dad05e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-portal@sha256:cbbd7ed4e19664397edae6bf27d7fc81133816809ba0ea973f7389cf17cc452f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-portal@sha256:892e7615522ffe54e453ece79faad64330bd9bb1716ecf15e3eda734e7a17f39 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-portal@sha256:442fd4abcefd6d895dcf0104e3f195c5d9e4b2c36787570056f35519b8cf424d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-portal@sha256:9561818f54fbe86de46d71eeca8e4ae9ee300863517f4bee1557bb7c4ec1bea1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-portal@sha256:5d57202512f10b0e660fb7b0c660f574a120f9042dbab21da14edb36374f3d2d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-portal@sha256:b2b16fc92c7266e80971403b669a826514fc9f8572b11980b37fb263f8c06c22 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-portal@sha256:375926f9fd2e3c7cd61c7d1f8a2f08873bc7732acdf6bf098413aaf223822903 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-portal@sha256:6feb0bc4499240e93f8438c0488c76ae805a315c28b6cdec3313ae2e7ae2cf6f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-portal@sha256:11c5be6a168f4a50c60a7aaef162986d1102ae654b4ff684d3129f5d122a0459 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-portal@sha256:f1cf14f59d1fe8d9de6b936fd281c1c030579b1bcf97fa66f54cba3b9df573a9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-portal@sha256:5176459ddeefd9d06e958efbeb8712e7c2ae4ee29a257ca23a4cd237512b8a81 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-portal@sha256:e46499fa3ba8ffb2d10a136744fe83c10299bebd7eb02f323db04b67817042ec |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-portal@sha256:7e4277cf45fe1d967fb537d22b502ffc92602fe7c1599df6ff17eb4ceda8d968 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-portal@sha256:9b15dc4236f1bdc37671d0651082da97e46a4514599d9d8d7ad8498e38dc09a2 |