dhi.io/gitlab-container-registry
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.42-debian-fips-dev, 4.42-debian13-fips-dev, 4.42-fips-dev, 4.42.0-debian-fips-dev, 4.42.0-debian13-fips-dev, 4.42.0-fips-dev
sha256:cfe23ac6ec4b141cb573da7aa2b6262bb17facbea40e533494cbb359293911e9
Manifest digest:sha256:f0f60873e3d55fe70a84a3a1f3bfbfb371e1f49ae378e8fe57b69ce4161e6d97
Size
58.55 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-container-registry:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-container-registry:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-container-registry@sha256:5901840298dfb1b142fe47f348fca038cde2ada47f6a61c8f7d182004b4cab67 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-container-registry@sha256:fb7d175e04cdcc529558722ec477347e4e3bc24505efb493fd92cf5b18c99fb7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-container-registry@sha256:c65df420aa0689872f9fdb8bd094be1e15d9bba231b090b92afb73a1b168d369 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-container-registry@sha256:d6b482807066728b465510b7e0fc0026c7a23726477f715fb4809a1fadb37daa |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-container-registry@sha256:58012beccfc58a02fd542610572cc18e7505f49e9ae6fb231f5529c3f2a8d5e2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-container-registry@sha256:1115f3b9a3f927464156eee0ee17de6ae7da95839a2d86f3d05dd83fba8c46e3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-container-registry@sha256:bdcf0b241dc238a644288a7a9bd06dc072ce323f1535baab0ce8795a9867288d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-container-registry@sha256:6cdf3834dc2064f3bcd04bebb57a4a8039693dad10e8d0c22ec1504de7a7d61e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-container-registry@sha256:19d9b2d81c642897c97fe0091a4de122672b48984a1d31b03fe9e4e9d9756dec |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-container-registry@sha256:0bc3f9a947b8cd4e2eac651c4996c87b8bbfb4e5017c5b96b1eb5b3c764fafc7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-container-registry@sha256:23317c3576bbe59061f8d397f1fdbd7fde5270391ce9ef459af53afa389bedfa |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-container-registry@sha256:c97f280cd18cd3cb0e22fadfbc4f4fb7e058b9d32d6c7a38cbce55afaf3e3184 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-container-registry@sha256:e0916f9d21cf27b97a9e1c0d3bd0b162f64956bc791920f38d2249209fecad0d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-container-registry@sha256:bf76596ba8b59fee95b7cd68ed2142f87fe16a1d6748a449bcf999739a147eb9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-container-registry@sha256:39952a2b11afb35c787e5f5d99d1a0047c77860b60930f8a7af4085f61990bd1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-container-registry@sha256:d9b2ab8666acea49fe1e74cd8d5fdd68a3aeb76c60c905a12d2deb5514c1a796 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-container-registry@sha256:95865b12669792cd467bdbc9294e14f9f9fe4967aace9593d9229f956e2988d9 |