Sign inSign up
GitLab Container Registry

dhi.io/gitlab-container-registry

GitLab Container Registry 4.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine-dev, 4-alpine3.24-dev, 4.42-alpine-dev, 4.42-alpine3.24-dev, 4.42.0-alpine-dev, 4.42.0-alpine3.24-dev

Index digest:

sha256:89b520f51eb2231523f5b4fd6dd7e251a35345b3e3e40bcbc5a524512a6a99e6

Manifest digest:

sha256:467962c7a1c93f1c30adc66d649f9a257f950bd24d2b0229ae0c727e2eb89d58

Size

38.36 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-container-registry:4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-container-registry:4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-container-registry@sha256:9b268cb061aca3cc66904c655d2f0d6edd8cda4d416ab5a28ff1c17f554421e2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-container-registry@sha256:408bc35a0da4bf752d27c0f9f5c6c6bfec7ca1fb7eb5200a916fff705d37b2df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-container-registry@sha256:53d50683a9f08d4d383c585bb136ef76059e0bb8c5e4544aa59f73bc1bba9bb3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-container-registry@sha256:7fbafc0814902563e174fdd5a76eeaae9f3a705fbce4c2142181fff428c3e0f9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-container-registry@sha256:c612cea46d339177764fc8e5c4dd8dc6c0344d0a7aabf4865a1eaa91ffd7da29
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-container-registry@sha256:d23ce8e909160993aedaebe675df5dd834129ff29cc362732868f66039a8ce1f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-container-registry@sha256:01bf397950ffe955bb241f41783257e8b8b125c9081d7acb445c523c730d815b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-container-registry@sha256:5498b673d104dcdeff1bdb7240307e9f1f637b6e64c89ad78db825de487cd923
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-container-registry@sha256:d04d4ac89caebeca16c1b996c1ab06ed542e549e239114134a64b79cb5c81a2d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-container-registry@sha256:62076d6ab690c48421e2a652afcb6851afd478972350245db900cb56c24fa757
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-container-registry@sha256:3b6eac167e2fa326df2b05240b442ddfa8e3aaf1607bda77c543113ac0b8ee87
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-container-registry@sha256:4fbe71e513cbf247d0c9554d5e4841e033a3040afa8053977104d0204e72ef50
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-container-registry@sha256:156584e7a59343e64fefb1cba9d777ced73e74d94b0ddf3d1da50fe61195c324
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-container-registry@sha256:04125c209f8e8e1f810f8d26147fa3ebc4988f8ec58ba5a84c0deaec46dcb256
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-container-registry@sha256:f4f8c762034f2e1002d5e55d655783ac037dd53023942b8b8383881cf564ff3b