dhi.io/gitlab-shell
14-debian-fips, 14-debian13-fips, 14-fips, 14.57-debian-fips, 14.57-debian13-fips, 14.57-fips, 14.57.6-debian-fips, 14.57.6-debian13-fips, 14.57.6-fips
sha256:5d81c28e12529c6d356c48f2658eb30c53950823a70d77b0bf163d48518483e4
Manifest digest:sha256:bf3d43410ad6b88a89fc91e24c4c6150bca1837d9530f43c380d7499b7b2f9f5
Size
88.08 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-shell:14-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-shell:14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-shell@sha256:e315809df17535ace2e03ed7398fa00bc7e60878c2392193fa101eb6ea00325b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-shell@sha256:8803e68b26f1aee4d727490685682128f1c7cadbba8269f2b48fdc39cb49befb |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-shell@sha256:f5bebf963400f96f26a2482dc038eeeb33c90c91d167bc2831fd163b2f951e62 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-shell@sha256:40e3eb23f23f3a9b152e5512df8d78b3bc459f578ba135f94c44b6227700f258 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-shell@sha256:da3ae6d2974cca7e7d15350253b199ba41fa17b85507f3fd35ce3f3370d53960 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-shell@sha256:65130358714de021dd9ddfd50522215e4840a36810a5f7615089e6ddc65b6f68 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-shell@sha256:58aed4bd7602f916690624b8f2e2401b2f2a09891db1ab1ef22ff1482a69a5e2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-shell@sha256:7d287c95aeb978f1d366f494aae07a924d3250f27b24f17ff42d77064360c446 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-shell@sha256:483ec9e65613dee21ab3c52b92cfcec654cdf8084a2c03c36dfd32a0455fc44e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-shell@sha256:6bd3c5ad44a7acbaf0178e7affe4b58c8eb4ffdd210f189827252d767996ca9c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-shell@sha256:2f79afb4f3a04b7ea714453085bfeb14cc2490ff967d2c675a63e4933b98fb80 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-shell@sha256:55a3428b9aa3094535dcc4930ded83f524ca338ef1c8d17e75168b7e1e2d0387 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-shell@sha256:75b7b880c61a31034179ae9835e48065c41649e81036f9d7fe0eca31039d8936 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-shell@sha256:df4fe1f41ee4f4ab75b930c28b3f14f84ebbbd07303c8e40dfa084d59a143464 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-shell@sha256:e4537d847717ce1a8ad34bfab98f6fbe73ed3d61a6af4c90029081fe1bf3c684 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-shell@sha256:1aab8e1b665708ec5a2ce3e14144ab58cf0b8b1d7ca3c13deada084040c34360 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-shell@sha256:9c6be143478679e925e56dbecd14c4228e10ec5d90c25d79f13014e55f159e71 |