dhi.io/harbor-registryctl
2.13-debian-fips-dev, 2.13-debian13-fips-dev, 2.13-fips-dev, 2.13.5-debian-fips-dev, 2.13.5-debian13-fips-dev, 2.13.5-fips-dev
sha256:29b4f3857d50924cb6452ea23228dc54eef5740682c938746187c880c0385fd4
Manifest digest:sha256:756d8950ea615bbfc16f8d8336d7008b7578b083a368272e84668cc71fc84e8a
Size
39.02 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/harbor-registryctl:2.13-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/harbor-registryctl:2.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/harbor-registryctl@sha256:6f7335ba5dccf9aafd840aaac32d23035e8ca507b955543b1e5d3ed0c0d26252 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/harbor-registryctl@sha256:1aa36ffb0465bf4c5d38d2d86e5f15c7758d7c6f894a383eb3a802b502d31f74 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/harbor-registryctl@sha256:0b1b363d1da5ed716a7c41619a647b3e31186f73f3ff1cc41c4d1ed1c51088a0 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/harbor-registryctl@sha256:2e5dd0f6784c2fd08d4bcd2e1eb15206ea5bf586c4ce8132cf49dbdb3d23746f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/harbor-registryctl@sha256:16b8a209ce2acfc6489918e56b56f9969e1fd3ccbde870801b76fe591a8661ab |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/harbor-registryctl@sha256:32923b44f68a81ba8b63223df361deaa4694f5c5358cce3fdf2768ee77056334 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/harbor-registryctl@sha256:56b832cb7f17b27dc2724ed1130af5cc6752961cbd62ed85d733305569c6ee95 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/harbor-registryctl@sha256:a554fffe90984ed1e002f05cbae16aedb506f2f73bf0b4ddfd926c5d122ada4c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/harbor-registryctl@sha256:30d1bf7596a69e42fd9817540086a173858fb3a10ba7aa44845bd394d6a40d30 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/harbor-registryctl@sha256:341a0679eb06749ecfca05eaa5afb8c97e66031dde65b0e4b2fab54d7d637f1f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/harbor-registryctl@sha256:332b788d557418aed624329c6f5d970c7312511da4851ff38178589782a435bc |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/harbor-registryctl@sha256:4c2de4148b46fe12e71505aa2efcd9c2017a04a87a8a8cde632cc4ce1e765385 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/harbor-registryctl@sha256:3bc2a5a7d76a9c7407f96ad4743405a4435d9ff46241864ed5dd9d530c3c7468 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/harbor-registryctl@sha256:56fa4204e9708efcd8ad859c0c19c52f010a1d4e1169f2d4a666f1fff025609e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/harbor-registryctl@sha256:37e7e1ce3e7dc3e6a5a1fb2af4e48e758572e14080a57acf54aeef5c9f04e013 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/harbor-registryctl@sha256:d8c6dcae3d6d698b6927561050730e87dd0cb473ea7abe480c9f2fc7f7e2551f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/harbor-registryctl@sha256:32635b5656cb3700025aed7bc9bd5986b84aa92b21a2d54163e8c4c895e0dfbb |