Skip to content
QuenchWorks

harbor

Chart · Datastore · standard · v0.0.19

digest pinnedcosign signedSPDX SBOMSLSA provenanceamd64 · arm64

Hardened harbor image, built from source on Wolfi.

Version

The latest line lives at the base page; older lines have their own page so you can pin and verify exactly that version. Only the most recent releases are listed — an older chart pins an older image digest.

Deployed image digest

sha256:5dc9b1d47431636dd3733f9156560b7367e793dbce4daf06d7689c287234c1b7

Chart OCI version

oci://ghcr.io/quenchworks/charts/harbor:0.0.19

The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.

Signed
cosign keyless
SBOM
SPDX, on image
Provenance
SLSA build
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
Root filesystem
read-only

Install the chart

Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.

Install (latest)

helm install my-harbor oci://ghcr.io/quenchworks/charts/harbor --version 0.0.19

Deploys image (digest-pinned)

ghcr.io/quenchworks/images/harbor-core@sha256:5dc9b1d47431636dd3733f9156560b7367e793dbce4daf06d7689c287234c1b7
ghcr.io/quenchworks/images/harbor-jobservice@sha256:49da7eecfd3f724343cf50eac98f9a37eeae2b50d08fa9c729be7647d59369a6
ghcr.io/quenchworks/images/harbor-registry@sha256:b9cf2060b2a5ed97096b1267a687bc3a7f7cd13c5d1f53474655f72173a552f3
ghcr.io/quenchworks/images/harbor-registryctl@sha256:7e0e7599e7980e069b2143c4dbbac1439c9ffbf6c2d99c10660f4460bbc897c5
ghcr.io/quenchworks/images/harbor-portal@sha256:c5cf43e186b5aa515ffd8685b9a7e1b7092f7f3b6e89a53a2fcd55ca7850ed40
ghcr.io/quenchworks/images/harbor-trivy-adapter@sha256:53669da0ebef6bd1dc5c68b860aa19d08b254821cb0aa75c91d35210078b3958
ghcr.io/quenchworks/images/harbor-exporter@sha256:4ff401f6365032cff05dd51280fe1d9c55873c0c11c402a1bdac1c557ec8789b
ghcr.io/quenchworks/images/nginx@sha256:19d9321dceb22f855c55789634f39872386e289912658734be374ed15203bf27
ghcr.io/quenchworks/images/busybox@sha256:96bfb56285a65f978985de00bec071bb9e52d3c588cd26febed64ff36651c526
ghcr.io/quenchworks/images/postgresql@sha256:919b69c5c86b3a2a454bbe50a24d9d33feb73441bb0d466e583bc3e1a78ac77b
ghcr.io/quenchworks/images/valkey@sha256:c9ceca7878908b8446397cf83d78c6eeab0e64db18b54111ff704184ee995cae
Chart version
0.0.19
App version
2.15.2
Chart license
Apache-2.0
App license
Unknown
Signed
cosign (keyless)
Values schema
yes
Last published
2026-08-31

Verify the chart

cosign verify ghcr.io/quenchworks/charts/harbor:0.0.19 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Transparency

The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.

Upstream project: https://quench-works.com