Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 18.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.11-debian-dev, 18.11-debian13-dev, 18.11-dev, 18.11.12-debian-dev, 18.11.12-debian13-dev, 18.11.12-dev

Index digest:

sha256:a81b457cc9524a2cc98f379fb5e1046d0b3fcb14e9ed37435cd6a7cb288e1e61

Manifest digest:

sha256:1065fed9871ab6b9509818224497abb98952433c99fdfad4b5d10c972d9a35e0

Size

537.57 MB

Last pushed

3 hours ago

Vulnerabilities

0
7
14
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:bb9d16244b3a6a0d96ceca465323e1e651fa832ebef41239828140d50bbeccb8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:1841b53b29cd09ac64e43653ea10d0fbc35cddecb78d605c8ac9d9b09f838d18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:3c67ab8f8114fdee370eda0d8ad2a3479207dc2c11d343e78aa5caf10fee4c96
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:2f1b24882740637a526108d9fa06569bdb167fcb668f4439baacba4e21a7c6de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:a399a7e6e2d8c72828c5ef826f5ca3f22e13bda8391122f29c63d2cf9c8687bc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:445f02292d1c79c792acddd70a4555dbffc924dbbdc42d70c1832a8a86d2d135
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:e6219f33aaefa80627d709d365b8624d347f8fa5399d93755f32d641d7e0f301
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:6ee1ee62a391cf34731e90e8f0eac93418df633ac8c88b590df4652da59d94a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:0b6e9ed591854156a2cbd91484564276c22cbb546517258f67d66790a6febf6b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:389efc2d0b1cb2daa71ec4976e4371d5f9ecaa74e8db30e77eb2af9f3d1e583f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:8b79f7d28349ae87a9cbe033f7818c52e531880f763f8f27375b45dd6c0d6362
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:9f5a7f032213e4b6bfb3b3125ae71e0ef22b2f0fe85a681876f9003ff3909fb2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:d5211f7eee5e18b634ac68c5df66bbdf1ee9e77a47baf46dec8ae447bb3f890b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:6dfbf0275a2647c0516f1d665343069cb398ca39f52a5abf66c4da24f2a5815f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:b63ca9543d70077ed75888303e83cf4322cbe374a0712be70cb69b2fd1350c74