Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 18.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.11-debian-dev, 18.11-debian13-dev, 18.11-dev, 18.11.12-debian-dev, 18.11.12-debian13-dev, 18.11.12-dev

Index digest:

sha256:414b0f4d3ea60ef039b7126246816f5f5e8d993ae9787fca0816d2d991b5d556

Manifest digest:

sha256:3db2648418789b5de8d1ccfc1dc99ed3915b58e3d9297dee8af26109cedc852c

Size

537.51 MB

Last pushed

10 hours ago

Vulnerabilities

0
8
14
6
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:a40ebbac9fce0542d31567c8ca88dd4dabeb5ed749095ce4c1daf865447faa2c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:205783412bedb55b17ad6f3b9adf3fa565bb214ae4ba1ffc66e821411ef38f65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:655554511bb96133ec966a924cbeedf0af0c536793a770695953ab44eafc622a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:ff12770874c2fb06894c2486c5e2949631268bb3be938dbc6f2529e98c076104
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:50aee122add043a2d649428de1c69933b333a85e0e57202bc4f602ee69d55ba8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:d6fbf98611aa13563ec63e2bc99b5500133d5959f8305243d6a326317a67728b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:3e65b8de4ecea5792d7b62b87d23e3bddebda6fdc9281683ba94561fce2a0b32
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:1a9ed74ae27dc8124b1f127c68b0d682a2d92baceec95fbdff60226d1ef1747b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:0a96dd73475cd38c4216cf21c94e118879ba428768e0322c75353b005134d7f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:78950402df5d452fa2d151145246a819bf36b1353e98937a8fb02e7246213ccf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:261f0d3f8ea65cb7d64fd497cb79ad470ee5d9774d1e7b138c211b6e2cbcb163
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:1e013e98a908992a1a1abbde0aea5537c1aad09245356476caa101c6aa7b851b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:398c0362f118b5da779570170ae4964f3321e0955810b5c25aed908f5bd3826a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:1fd96bf4aa60838454a1fe5f79f74651074360f771eae89cbf572f8fd87742a5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:6823914f8e47f5f80e410db5fe15890f70ce2be904fb25012238ebe613d3d2e3