Sign inSign up
Harbor Registry

dhi.io/harbor-registry

Harbor Registry 2.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.13-debian-dev, 2.13-debian13-dev, 2.13-dev, 2.13.5-debian-dev, 2.13.5-debian13-dev, 2.13.5-dev

Index digest:

sha256:6d3b5dc086843e4b1e3e9af6595ac121308f88d3083c0be466525832c7ec2a0c

Manifest digest:

sha256:b20af7097e560fd80f2e887682fe4a67594dd94e6da162e7d9ca3f4d107decf1

Size

36.68 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-registry:2.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-registry:2.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-registry@sha256:47493ba7aa3eee23457ea94fbe0e24b343b189eae28d0eca18016563aab0a695
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-registry@sha256:95bcc361f1bcd8c9d9b04c0d1adad4551852c31de482c84a6a57bc2d4a51b539
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-registry@sha256:4718e47758ffb198497e697f4780e96979329e91aa4cfb5c663963972cdc1798
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-registry@sha256:1c5143df7007f9967948c42793a27a9f71ca5fcb0ac7e9f595bf4673a7b56ee6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-registry@sha256:f41905b0b92e36251eb83022158a1822f576e8431764f0b51cde3842332baecb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-registry@sha256:983933f1897f62562fba054357333413de646ad761dc44b47ef74bbb51616e14
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-registry@sha256:6d6e660f7e12ddb6fe1abe9f54f663efafe7af590b34c3ae0eaa1a759d984c93
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-registry@sha256:80db883cf3fe62baa1f40c9ca78ed8a597537433bf4394af2616c6d53f6c7b83
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-registry@sha256:d9b1956dbb17caaac282d09f487e87301fc45d4bb5c750368a821e87c097fdb5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-registry@sha256:910d0bdce40f04127e0040c7f1502dab1b76c3c7e25914045e25bf7285345576
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-registry@sha256:e9d035833e52e213bac290e7ce481a3e1f628f477e5a9d317d10ea426aa35988
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-registry@sha256:3dabf1282375ae7f8da1a7014fc131e52e2e63afc9a776fa7029600c41a3060e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-registry@sha256:813352f17bdea753f14fa10e53a939d005db27c394938f7d7d65fb9d55d9ffba
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-registry@sha256:2bf3e083b90fc733daedad01bfa70bfd8b3510adf5b66b28e0eb78231877a468
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-registry@sha256:bfa02f2c1d05b16b376267c81777d36a137305d76eb833462dc5ce93f7853ada