dhi.io/harbor-registryctl
2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev
sha256:b25f865888dbc8a70f3d21a7bcd14fc98f8a5d4ae312bb63e8f7c922f50929c4
Manifest digest:sha256:7b444ed1af38e3bdb0f5a27890777718e8fff17ac8dad38e19e9510e5d314fee
Size
39.01 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2.13-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:c9da0f938fffaaa98d60e4233078d4811d91abc03ed1340b772c2d7cbccb0830 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:dfc7f302e2fc858ac619e3bbc9aa3e0af2179ae6d0a6c3536e72f8b3e11ea207 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-registryctl@sha256:1ed02ad04e1023d1549e9ff812b2be285f3ab989397a907d12b0eccd42042400 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:906a198790cf27fd8bbc5501698f7390773012f8235b43c77f9dbeb232a5969b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-registryctl@sha256:253154fae6554cec96abd25f57440b3726dbb763e14a1f29a245387c21650ac4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:8f47de0af168a39c67614bc0da8e9551647e00673f780df4491dffd395cec98f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:714e57715c1814fd5286173b772bc12b919672e908fa7544e447fa2cc9d8b831 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:550487104a85d7c263e841a23046e431659ad37126ee63f6ad3785452d3ca045 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:fc3809c7277c958641973242ccbab5a9c0be7772905bc76c0d7d57c8f100b4c2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:4033d58b9fb2ac74933f7371742fa7779611e2906e45a3b28730aa1b812484e6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:2bdc4eecf8516df6213beac53c2a896ddee1eff50e045a3a9842821a6d2ac004 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:40e322d76719d7df3014b1661125563daa80b1aea4aae47d557dae319c1bb33e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:ebf283d6408695bccc0ea52862e59d2f5b02675513121351317e56de95727ad1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:2b2053a2d7c5f8a26455cceb89f3c515f1c757c3f9ddb4260d5d93c1896dcaa1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:c1570bd0b442bbc722ce740aedacdbf0eff5756257d59827e57c991123588eb9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:2af5abc65c44e3a7a28d0076483a7229a22c96ada06d490fb063a0afcf6f4275 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:410c8bb8010a3aea49af3d62e56709aae7e6457b44f3e0dce706086b709ffacc |