Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.57.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips, 14-debian13-fips, 14-fips, 14.57-debian-fips, 14.57-debian13-fips, 14.57-fips, 14.57.6-debian-fips, 14.57.6-debian13-fips, 14.57.6-fips

Index digest:

sha256:8d58fca11edd03dba65fa1dbcdb3406a1b1b6b86fb11b2d2eabb9cfae2b99536

Manifest digest:

sha256:fcccbc7d51f35fcb0ff276c136ae43e632cfe8ba9de9bf8a0002bd65a938e5a2

Size

88.08 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:369943701895f1920f93984d948bc9aec66e0117598439d41303a08df37ea422
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:a078fb4fec5d65bfd04ea70a0004b0290ea29b3b0cf06a46e54087a528093957
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-shell@sha256:e91fdb563d017d4b1c91ba190cc2ecbb02f9492c6ecbab62caa680856c508e10
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:aefe0e678446026e878f6d83c2dc526206387e21e977d595d4ecb3c20b0f52ad
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-shell@sha256:e1b8eed64ba3a5d046ae04459fe7ac23db898d0e4da525526e025f92535746d5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:a5c76c2202d2492f80eff3bcdb14b08ac4735ed9c1ac14106ca2379cf84191df
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:3d8660447092cd03c46ccb83993c1ba0764b821c1a12aee8e80ac1b7f72d4330
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:eaedb8ebe6dff245791ed559bf4f1a875e0354ee2501a00076368cac17c3b445
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:01de4c7049783c96701c9a30403acf3057c28d0e4a0c599621be08ba3218a249
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:397fd4b25061efda9bce452ba19a17124f0d9cdb4d59d62f748135bbbf5930ec
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:0d7ca463bba0bfafd7b6da3ec2b0305a85170a19477564359172239924626f63
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:a6255f91f43a4b8fd912d36b1a063324da714649df70151a5f17f2ac532f4d89
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:e68cd4ebcc1d06d45e293addfa53e2c4bcaaaa1741f9fb0739edf05dbb7f61bf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:414d8451a03cb978b6fe52adb205c7b420faea59c3e53d4101cbc4279a370204
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:b0170ca1f43eb55a7da791b5d9dbc5c499fe12c761632abfcf1cd3eeb69f92cd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:b89870b9319639ba7bb972636bb42dff98d3a7d6a97ed76debb49889e3b0e968
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:a2ad9ec84ff54f71f6d0c5a1b1b3756e930ca1cd78700b884a02eb29a2dbcbb8