Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.58.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips, 14-debian13-fips, 14-fips, 14.58-debian-fips, 14.58-debian13-fips, 14.58-fips, 14.58.0-debian-fips, 14.58.0-debian13-fips, 14.58.0-fips

Index digest:

sha256:a251546d99d503e93c3b311b2db226c8e6661bb9cab38643c899a25a141bb269

Manifest digest:

sha256:1394ae488cad25d2343589fccfff766de0854d7a9b21ae98ee20615896dd0507

Size

88.09 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:97d4d16786638302076028ef104a0876f9dc4b491b4aabf6b530e7f2cd28a8fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:c3d7ba91c10fcadc01185f5a9f9eb60f962a2875c06cfcaa89395c7f737d965d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-shell@sha256:4bf5fcb645adef71328a99595ffe667554e60b0a7abb78a1b33c9b5435bc980e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:9c9ccbbf0d7928c18be88f806af066861302763a07fe0f207bae0fdcd3201a87
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-shell@sha256:4b379d46d985abfbe2ac801164b8e6ea9b31c034e0870ceae488e20dd0865473
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:70bdea99ee4f040d3436ed9f7fa680c7297e5fdd04d3cb5458ce3c729f50ce15
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:14b75f2720b3dcd9be2bc86e870eb9223ee3b9fe8aa6e9557cc13cf7cfd1146a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:91f01f34fc9bb211b43cd5403c3b0214108d33f5bc176a483852edab470f034b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:e365d652a20f1877ec7d7a07e901e7aadf34799e864654469ec8f0fb602d4271
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:3668bc297e0f0929f5afd7fa6ecf13160fb63575a3eb665a2d7292998345ffa9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:cb935f9ab0e504bcd20f427156b6a39767932bd9949009324d32977928679261
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:ff3b644fa75797b36c2ae49ebcedecef27aad7b72b73e6232890c05a1f5fd63f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:7fdd9cca456cf136b99ecd6f222d2543a5e7f568c1023fc04f1be584fa1af78b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:82830639f6ddb1a7f06c904f1e1b0521aaab727bc1c14d9f7f08afbdc78ba752
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:a15a164c813bd11a0a1b19e84927bb95a95716e792b461e0dce825593188ed69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:5a7eec708a41153c8312031f4b9b1cdfa5469f2c0140c99a06580cd73dd8900c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:e8e5a7c4e3fe56a427bbc11be275160a3ee3c98672c214a6b4e7e8c48aa51b89