Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.57.x (dev)

CIS
linux/amd64
debian 13
Tags:

14-debian-dev, 14-debian13-dev, 14-dev, 14.57-debian-dev, 14.57-debian13-dev, 14.57-dev, 14.57.6-debian-dev, 14.57.6-debian13-dev, 14.57.6-dev

Index digest:

sha256:c438731dfc7e57ceab4e2798a48f29b39965d8ef3916154c2dbacf2cf29c0ae4

Manifest digest:

sha256:25efaeef59efb1be71126120ca668ee51b76533754a8f144cdabd547766eb75a

Size

97.41 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:6eeb2396a4cccc5d922d26532e9bf4ab3a950530178181e425b1a3cea3ad0f58
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:40de81892afb3aef0c218883e4e9f92c87f0585afd825e00a137a4a617fe914f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:3e3bdef820066fb96580832110122e8e2187fc796ad31183ec84f16d4d55bf6a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:3112c7afa1aca1c3ab0e7a82332d103568b3f14a761637acea707654c00405ef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:fbe619c14b5a4cc0d26578a93073aa6d18bf38a92d118b597eef0d47316766a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:3aa4c93dc6a81dec4130cc9182c521ca49d2989dd89d194a1727eb21ac0ecc4f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:469a8d28a436da33b117cf6421a8e437117c8193a1c7bb1d3f14b4a1e14dcda7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:4bf1e3026fbefe5b3c7c121f48930b2e96cd51b265413973a28a130a0b777f41
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:b412b64c42edd2ac9e510e26087d7e8f901d128db2e85e5d758728b8db862615
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:833137f535b1a58a1dac6711165d25f3882febb0d55d34f04b6f2ebe847350a4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:afa12e14f1717fdbb2b5e25c16c4870c2532b34f5e0dec3d4b832f44058b190f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:38eed8f78b49165bb052fe07eb9e02c26a2e07d079d9f5bd5dabc920ef4be893
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:8e1d6dd0f26562bb6f9f56eee228d34e91c18412b5dd724b57dc8581c8a18c3b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:b4fa4f770572d4e9e983916735b0c93fd9977ca95aefedc1ca3771e032f87e8b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:0c55f072697cbe2943271181325605ff79006544e4468d55121b8370d27c3a26