dhi.io/gitlab-container-registry
4-alpine-dev, 4-alpine3.24-dev, 4.42-alpine-dev, 4.42-alpine3.24-dev, 4.42.0-alpine-dev, 4.42.0-alpine3.24-dev
sha256:89b520f51eb2231523f5b4fd6dd7e251a35345b3e3e40bcbc5a524512a6a99e6
Manifest digest:sha256:467962c7a1c93f1c30adc66d649f9a257f950bd24d2b0229ae0c727e2eb89d58
Size
38.36 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-container-registry:4-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-container-registry:4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-container-registry@sha256:9b268cb061aca3cc66904c655d2f0d6edd8cda4d416ab5a28ff1c17f554421e2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-container-registry@sha256:408bc35a0da4bf752d27c0f9f5c6c6bfec7ca1fb7eb5200a916fff705d37b2df |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-container-registry@sha256:53d50683a9f08d4d383c585bb136ef76059e0bb8c5e4544aa59f73bc1bba9bb3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-container-registry@sha256:7fbafc0814902563e174fdd5a76eeaae9f3a705fbce4c2142181fff428c3e0f9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-container-registry@sha256:c612cea46d339177764fc8e5c4dd8dc6c0344d0a7aabf4865a1eaa91ffd7da29 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-container-registry@sha256:d23ce8e909160993aedaebe675df5dd834129ff29cc362732868f66039a8ce1f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-container-registry@sha256:01bf397950ffe955bb241f41783257e8b8b125c9081d7acb445c523c730d815b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-container-registry@sha256:5498b673d104dcdeff1bdb7240307e9f1f637b6e64c89ad78db825de487cd923 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-container-registry@sha256:d04d4ac89caebeca16c1b996c1ab06ed542e549e239114134a64b79cb5c81a2d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-container-registry@sha256:62076d6ab690c48421e2a652afcb6851afd478972350245db900cb56c24fa757 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-container-registry@sha256:3b6eac167e2fa326df2b05240b442ddfa8e3aaf1607bda77c543113ac0b8ee87 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-container-registry@sha256:4fbe71e513cbf247d0c9554d5e4841e033a3040afa8053977104d0204e72ef50 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-container-registry@sha256:156584e7a59343e64fefb1cba9d777ced73e74d94b0ddf3d1da50fe61195c324 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-container-registry@sha256:04125c209f8e8e1f810f8d26147fa3ebc4988f8ec58ba5a84c0deaec46dcb256 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-container-registry@sha256:f4f8c762034f2e1002d5e55d655783ac037dd53023942b8b8383881cf564ff3b |