Sign inSign up
GitLab Container Registry

dhi.io/gitlab-container-registry

GitLab Container Registry 4.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine-dev, 4-alpine3.24-dev, 4.42-alpine-dev, 4.42-alpine3.24-dev, 4.42.0-alpine-dev, 4.42.0-alpine3.24-dev

Index digest:

sha256:76ca239c9dc8a5c34e6b56dfdd2e328cbedf4fd9176227d3481bea09498d0598

Manifest digest:

sha256:c7e79f06433c8fb8263f2f470ccd54130e314f7b5c236289e46ef94363c0b6bf

Size

38.36 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-container-registry:4-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-container-registry:4-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-container-registry@sha256:49d6ff70f8fed50ea337cf5db3b5b26a143f2d4446e63f598451b3f8c64667f0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-container-registry@sha256:3f11b6ed22d2bf9f3f917eec48a49eca39cfc526a1d4f03d71ef5b29fdb474f2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-container-registry@sha256:7c3f944e6c9c157249aa0d04d13ecfa5176fd6a708df806e8af3089400fe929c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-container-registry@sha256:a23d610b3f679f89a1d946aa0817c6eeb991e526b980732276c160e0c0f450dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-container-registry@sha256:371985fd56c0ba77e1b6fc4bfb228fd3d37b36404d8703d4a2b6b95ffbda1f1f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-container-registry@sha256:7a436f9c70066812df3ca615850c8bd23755b047fa48bc634c4e1dda73f8966d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-container-registry@sha256:f6ac0a2de7a1e2c965db9556bcd0d1c2d7718e8acbe312f67892b393961d31f6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-container-registry@sha256:b3b17dc88db8132beba093211fd76e7764dc4c4068e4cab3a1b4b9150be591cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-container-registry@sha256:d55ef4636f86cc17ca07fe73540b2a2bfb3c1705db7e018bb29ed494089378ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-container-registry@sha256:2a167d09fbe3ea671f58505a7881d562307a7c26a89fe10a2dfde18bd502e145
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-container-registry@sha256:f77fcd1f94544bd206f6162feb461fe458cf5ca4e8cb5ed29601d03796c77b0a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-container-registry@sha256:a9be019e95e1750a7292482e4f74636447b061a19a8f9fb0ddba57c2b0adcf8a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-container-registry@sha256:666934d992bf4c37ff25016a9ef717deb73f0fbbe02742fe8d1a4db340f48ab2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-container-registry@sha256:70e0a0c2e2d79d754cdb3298c7e10638db8086398c867ac26a2763915d1d5045
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-container-registry@sha256:294bc37ec579ec511490a72a7fa6f556cc639b6a0067d130399283d888a5cf33