Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.57.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips, 14-debian13-fips, 14-fips, 14.57-debian-fips, 14.57-debian13-fips, 14.57-fips, 14.57.6-debian-fips, 14.57.6-debian13-fips, 14.57.6-fips

Index digest:

sha256:5d81c28e12529c6d356c48f2658eb30c53950823a70d77b0bf163d48518483e4

Manifest digest:

sha256:bf3d43410ad6b88a89fc91e24c4c6150bca1837d9530f43c380d7499b7b2f9f5

Size

88.08 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:e315809df17535ace2e03ed7398fa00bc7e60878c2392193fa101eb6ea00325b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:8803e68b26f1aee4d727490685682128f1c7cadbba8269f2b48fdc39cb49befb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-shell@sha256:f5bebf963400f96f26a2482dc038eeeb33c90c91d167bc2831fd163b2f951e62
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:40e3eb23f23f3a9b152e5512df8d78b3bc459f578ba135f94c44b6227700f258
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-shell@sha256:da3ae6d2974cca7e7d15350253b199ba41fa17b85507f3fd35ce3f3370d53960
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:65130358714de021dd9ddfd50522215e4840a36810a5f7615089e6ddc65b6f68
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:58aed4bd7602f916690624b8f2e2401b2f2a09891db1ab1ef22ff1482a69a5e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:7d287c95aeb978f1d366f494aae07a924d3250f27b24f17ff42d77064360c446
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:483ec9e65613dee21ab3c52b92cfcec654cdf8084a2c03c36dfd32a0455fc44e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:6bd3c5ad44a7acbaf0178e7affe4b58c8eb4ffdd210f189827252d767996ca9c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:2f79afb4f3a04b7ea714453085bfeb14cc2490ff967d2c675a63e4933b98fb80
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:55a3428b9aa3094535dcc4930ded83f524ca338ef1c8d17e75168b7e1e2d0387
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:75b7b880c61a31034179ae9835e48065c41649e81036f9d7fe0eca31039d8936
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:df4fe1f41ee4f4ab75b930c28b3f14f84ebbbd07303c8e40dfa084d59a143464
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:e4537d847717ce1a8ad34bfab98f6fbe73ed3d61a6af4c90029081fe1bf3c684
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:1aab8e1b665708ec5a2ce3e14144ab58cf0b8b1d7ca3c13deada084040c34360
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:9c6be143478679e925e56dbecd14c4228e10ec5d90c25d79f13014e55f159e71