dhi.io/harbor-registry
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.15-debian-fips-dev, 2.15-debian13-fips-dev, 2.15-fips-dev, 2.15.2-debian-fips-dev, 2.15.2-debian13-fips-dev, 2.15.2-fips-dev
sha256:72cfee76b2b3c4765bbfb8f37f5c9b843a173ca81cbcdb11f0ca297c933ac8ea
Manifest digest:sha256:318f0fba5eeb397a2d4cbecaa8aff5ca6aa669b11b229f58946655476616808c
Size
37.32 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registry:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registry:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registry@sha256:7c18c378a563528c864635662785743b5ce2d879b885902c6cc822eca0f0dd1e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registry@sha256:e583c05ac79afe58c13a8bd9aa24bae9fe5479d034c13032c133202d2f8659ea |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-registry@sha256:631bd25b98515edb0982000a120766ed5ff40aeccf396ce691fe2bece0c4173d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registry@sha256:aa50190dd0774528802ecc7744415391e36f2bbfceac8ee2447db5b87ad328d5 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-registry@sha256:c30c60ca8d0881ca8f1a199b0a94e18f8ee98a35c4f38969c45a63586a649a28 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registry@sha256:9e27f8783aa699d0b632697f7a0956b415d3176e9d10a0ad9e42a47f327bafbb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registry@sha256:44012d6542db2159bab9e7c93ebc78a3cac6fd910906ea168dca46673b3a9ba6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registry@sha256:e88f992ac4bea4642ea67892f93a79a9a16455933b083fed7730d65d69f9e58c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registry@sha256:e57cb8148febc7c58fef910b3a95aace672003b6ef2ab3a5d701177399e56665 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registry@sha256:8a9e5c6dbe374a1fcdeb35e9e21aadf4841f52561352d84e3a9de833c46f86e1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registry@sha256:80ac5c368e749ec98bcac0ea586f1135f9f9f6413959af9e03844c6a7f62a7e4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registry@sha256:60b1a7f0c26d8e37039be2d5454121b020b2cfff5c25dfb7f0094e01f5d966be |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registry@sha256:7f940afa8004b2d083d58798a5960af12a5271798168a9809fd80ad7a4459ad4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registry@sha256:1efa091be9adf1dabf41ee94b5b6b30fc1ca32903711e797b7a4f478cc23ff76 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registry@sha256:a8d5ed23fc8957fbbf0f8e4aad313ef707a41c2bcd02095a4fc164911d9fd30e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registry@sha256:682d58b5992300907895738d122c3dd8c7a5fd260f215cc40c0d4cd465369f74 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registry@sha256:7212bddfb026729d173d489bbfe96e2aa29f0d3a2caf317b36ba96ceba09e28d |