Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.57.x (dev)

CIS
linux/amd64
debian 13
Tags:

14-debian-dev, 14-debian13-dev, 14-dev, 14.57-debian-dev, 14.57-debian13-dev, 14.57-dev, 14.57.6-debian-dev, 14.57.6-debian13-dev, 14.57.6-dev

Index digest:

sha256:45d69188eed4ad7da494e56d23a4ceda0dbe404095f6f6bfebfeabb855085a58

Manifest digest:

sha256:eec0238833f5c6938c9a2caee690a7aa751b7347008aa4f9ba3369d6d734a9a1

Size

97.41 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:04752e7f3596b52866cd09588e43bf893c4a37252397f1c5554cf8e5ce77156e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:788d2895cb9f9a676682ea94d5150538845cb3639e0be2f2806b8c43b61dec98
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:4cd21919d87a907c99457631ba855079045b354f32e71f6c1dbfeb98e0ab9632
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:2b663221442b51917d27d65963122959d93012339a9a57d32149b30afa619586
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:533e397338ed37dd3cf1d750d504f9f2e685f1aef33cd90b8fdb520c74b8eb6d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:5ad4d63ca7bc6fff0a3209ffa3e80d261af91578a7273afb0011429ebc7673d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:7259940ae569126ecc420462d4cc911ea0a5e42ab3a97b0b83fe6ce4fd604577
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:14f38331efa5c06568a3d69bea7b211cd23d5de36b08f82fabdb7286761849ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:09bf526339390216032bb8f2597900d2cca19015cdc13f37d76cb02eb2c55a9d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:2caf98b9345892e7cd0362e276f3828b51441d0c8e27f27f099e64733c457c29
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:d0d97da651916be54038282333e04b1a5960a26643ae9212a695a84181c1e39c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:04bd2b07050bfbfebc6d5e907ced5880d86a9340a5e612996de5993ab79c3f75
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:0a0cfa8e36d937235568ccdd926d1d3c01c65be180433e3baaf922e020b69659
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:0871a1327c423488061dee82e7f45785089553c435688d6a8bbb254d18bc3914
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:4af1882af8c0347d8d64c445a4b53a06dd07885c6268807734f7242499eb163b