Sign inSign up
Harbor DB

dhi.io/harbor-db

Harbor DB 2.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.15-debian-dev, 2.15-debian13-dev, 2.15-dev, 2.15.2-debian-dev, 2.15.2-debian13-dev, 2.15.2-dev

Index digest:

sha256:b77316b34241f9fa4370f8906129b7235379094dac84f7ec450483d697bd1b79

Manifest digest:

sha256:d353f837bf48fb50dbf211d6283147dae2b8c8bc3fcb24a23ce0295295746801

Size

73.98 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/harbor-db:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/harbor-db:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/harbor-db@sha256:4090ca9fdc4895245f50bbb271f95837c507b0ed7fc40ef870903cee84730dd2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/harbor-db@sha256:7c70174c8d132eccf4b30ad5a479b6f7d85b236a79322b2b8a4997a2fc1bb699
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/harbor-db@sha256:edf37f8fe1c2d6aa639979edfefde7a62acf234a6bd3164804eb51d79af0139f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/harbor-db@sha256:e18fb54e7ad7a72c65c3ae43e7c63aee3d9791bc90f911cc20cbbf22ae540753
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/harbor-db@sha256:054ce1b4553642935acd19f3eb7d0b18c901b03937fc85f47d054d14cfe0f859
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/harbor-db@sha256:755fb1370b4cffc8d06b6e2926579fc183b1242c26cc7c8ead20ee4b0dd865e9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/harbor-db@sha256:114388d463df710ade3ce413025707680f1fc67aa07ee45ec37986aefada05f5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/harbor-db@sha256:1297ec9c9593d4951d87d45fd425b12d7f2c7c5239499c32504cdad390108b65
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/harbor-db@sha256:6fd8b51f2a8ae473e32f683e24cdf5d2d2a42bf37dd5847f031d95791e3efb7e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/harbor-db@sha256:e5336b48fbc4da16e2c6cf9b0928c3696cdb25de1f962b2a0d9fa942fe30565c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/harbor-db@sha256:301814f7ebc557a5d7cc475d82a6ccb55d7546301aaa4c8da6527afd2e60435a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/harbor-db@sha256:cc2701568e8fa439d4aaed7ed35e5b86933fb9767020f5cf9f283b2d4ce276d5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/harbor-db@sha256:2788a80e3976227e9ef15ecf155fe87de53f8d576bea42202e5bb95d23fa1a13
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/harbor-db@sha256:91e20535c96f26dbbb5e756e19e8a5128e18e296e124765241f40730367df934
SPDX SBOMhttps://spdx.dev/Documentdhi.io/harbor-db@sha256:d45a9db5e5a68c413eda394321b0c63d18ec831bb283ab5713b7e56f727ba65a