Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.57.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.57-debian-fips-dev, 14.57-debian13-fips-dev, 14.57-fips-dev, 14.57.6-debian-fips-dev, 14.57.6-debian13-fips-dev, 14.57.6-fips-dev

Index digest:

sha256:c27c0ce0893b290d763d89646f0f4b6791331459a3491b47a9b593a38f6daeb6

Manifest digest:

sha256:8e49a11b709053b8d0c459b57a4849ca1ac4219e2e9aaf54f5d712e6b4ba53d0

Size

98.12 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
2
20
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:65b1d74a04e3c850e2c3c430e3dedd269f8cdc1b7adfc89b69141593cebd03b8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:3dcb704f36a269aed5d4b01a11fb65c8f52f7f7998aefe0cd965222a73ede7fa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-shell@sha256:0a2c6aa20edd6062551d005c9f67390fcbb91f587afd493a507d291172dbe54b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:68d99fb1e2f68f04f2a82bf49bbf49d302a85b987fcb47c5954bdce36b5084b7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-shell@sha256:dca5ef618867ad0ba8ce0a8c6ea3e2bafbf3faac2c6561a7ca7304661d2bb581
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:a99bf7cc413381dc0790b49fb4e4deacc114ac3943e0cd10b9d042eb941d6ef7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:b99c95994682b41359b974e47695709541d9147720c88e1a852ddb45291bd561
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:bc27a19d32d5087da85d3407f12c0414a959e124dd77ded6190050408b8e3b85
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:4b133e08485c0ce0174fa8fbf0c26e5542603a1c1c970362cd5fd9d4d2704deb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:eaf40806345dd830b7b7aed83b79ace142d112367eab3daa35aa32c1b14aed74
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:469daad888c31b9fd1fb01b6c8494f0b457690808f2426a7ceaebab98be771c5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:cd81006084b2429bed2641e203abde7a0fb72555a594d494d060ca4ce4f842b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:ed72c089be07d10567b3d5cad1df256077da5093a449058e83b3eb70e23f566e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:e9f5c47539bef17d961e00d9aecbeccc43f3f3fc157b546e228e04f12f390a51
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:6cd6bf86e58433c61df4f5dd01ebd4198476a55acc061c0ad7f2bafbb634395b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:7e7f6b12c3c972aa7f0c7a12f58997e2c09e1e07f759fa4fa6d131617f1f1df5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:e04b3be4d8bcf9c72c9c37d1428822a049f8f4b0a75d75acbcde65c6ee96678d