dhi.io/gitlab-container-registry
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.42-debian-fips-dev, 4.42-debian13-fips-dev, 4.42-fips-dev, 4.42.0-debian-fips-dev, 4.42.0-debian13-fips-dev, 4.42.0-fips-dev
sha256:033059f0e3e0ccab189ed6ca65ed209c121fb314c583aedad61f194d5814213b
Manifest digest:sha256:aa2eaba45f92939f3bd1b7e5771150b1f546f4a42429e7624b6b2f5dab81dd17
Size
58.56 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-container-registry:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-container-registry:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-container-registry@sha256:58a083e70cc3277c2113c5b19aefcf96c61b49e2633444c8e11d2eac1ee507ee |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-container-registry@sha256:c0307c84e32098bf4c3d84366c6ac17c8bf99eac25091141f6d21158cf995e21 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-container-registry@sha256:d0fd743a436922af3e52c1138b3f6a181751f8d61c3ab845916684d2204ac874 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-container-registry@sha256:76f23a0a0b8a6e655c910d86a29f5533037edb0cf9c1d321ea3d7b2be73a44ac |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-container-registry@sha256:ecfdd402c53f3dcda9e7e43210207d48f676d1210508d0fda6c2b28d90b27ee4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-container-registry@sha256:4d69ec40a26b2d7fe68de94eed13eccf48545161384c79a0b8f267430b854224 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-container-registry@sha256:0e7795e25ee0fb4120fb7e4936aac0ee52f6d88763f5013d6022dca83fe8a623 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-container-registry@sha256:765cbf0525f011d0f95e0932ce03dcdb2d1907e1dd9c32097af4e6ed334d7338 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-container-registry@sha256:74771db792f5de334a61a1b4f8da1036f4aab7c64cd4c1134822b20830d84abd |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-container-registry@sha256:9ce21ac7f87d103a9a4bb6b5b1a1b31f823f99ce22642dbc6197ffe0b587606d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-container-registry@sha256:113ddb978b9fad628e7c9ef59c5266d37a6ae800becde85ac2f19abf2c405243 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-container-registry@sha256:bec7bdd16cc5f9c134dde84e4fc3c3ee918cf0f3a00f68c501ab887892d9ef56 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-container-registry@sha256:6a2254f2b4eb7560f5262dc030e2c1236d8e9992c1c907d2b3515d1df40f6d1d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-container-registry@sha256:86a66e27e423f62791a3f0d389e927d5539022a04c7ff89402a9e7c1992f26d3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-container-registry@sha256:f336eaf23f98e50117e7ee4b5474c97a66362bac3447a14e6327cdcb428a7430 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-container-registry@sha256:d3918f7ee405a5db946b90de81e93eec0f32c9768be9c4870013899c8f1bca30 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-container-registry@sha256:933a9aa54d3e3c76651dfb4942bc96b54bc0b6dd5d0e4407348f92188186b674 |