Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.58.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.58-debian-fips-dev, 14.58-debian13-fips-dev, 14.58-fips-dev, 14.58.0-debian-fips-dev, 14.58.0-debian13-fips-dev, 14.58.0-fips-dev

Index digest:

sha256:fce3bb671260ee90bcc8d4e6787a0efa3deb8abaf2199d2fe115571693843891

Manifest digest:

sha256:84d59f400262a3afce5bc5d19e05e02042cecf4aec2522eb44a5bf3436e594ee

Size

98.12 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:e53e5365e9bc3385d126be1001a7a8ee67aecaae912214a8abb65a720c154985
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:c4c2b2bcb16108f1ddef100ea8bd4881b566212b9663bd829bbef019dd1e845e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-shell@sha256:eb398a87d45e604bf05b327be96a6372ecaac28c8e6c76495bd30316e8506e64
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:6b48ec2acadaee1e4a15ce24014fcadb5b109b2ecc4c77ccc6537cdcf69df4fc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-shell@sha256:bf7409d0c02ffb379abf93e8cb941efec8f522ead9dcfc516083ae962451b3cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:3bbd23abf242c96a9a82de6f624e9960243c87eedabc0ba95f84d8242951ee20
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:cb9ebe6959db6153d3a663cdada6bd6451abadcdc775f639b2b89710ecf208cd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:c3114060bfc6c6c040c0654072d52fc3283e5a56411813e59f14c86eb2874f30
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:c65601e743dee621507d52e809d18386dada51bc074add3b3a7745d0451ac6a6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:0c3fcfc0e45809b5dfbe212fec2d22c971c0f1d947ad57d54669cda950d4aef0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:4a8bedd8b550f8f8f52e3bc638b558b818027c4c00ad46e635f3880874e98fa0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:ac515adda075e37d05ec0e58c9212d6f337a5ad3081e02f00d402b15ea6c25c8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:dc959e7561eaf5c8b5d90ab89b1cb6180f19cb085ffaf88ae9cbf0bc32350956
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:2daf39cb8d87e4befb87c1dfeea79e8c39722208fa2fd223309682415dcfb093
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:d76ba2f6e70e5388c3b6a738daaa0ea74cb7c5195f6a087a88775ed11d911afe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:612c351975a89cb34c100d10ca2da53163c731840c1a1c7118c8c9bfbed93454
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:b23b4e18f1318c2f9e76fd6b96061aeaa604d67e6206d7595f7939e03ebfd51c