Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 18.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.11-debian-dev, 18.11-debian13-dev, 18.11-dev, 18.11.12-debian-dev, 18.11.12-debian13-dev, 18.11.12-dev

Index digest:

sha256:632f43e2f95e3939ed0173359b5a5cad3c6227b357b407b16ea3116f0cad25a1

Manifest digest:

sha256:44a4e9927c85a4186940d3e64059f21af48466bdd550ba057041799d3cb28548

Size

537.64 MB

Last pushed

16 hours ago

Vulnerabilities

0
8
17
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:06d64936f8e524fe75703b338eccd28233a827f7404180a317cdc0b3766be1d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:d075a3109b9be6eee47e8ca37b8a9e5815218430202e45dde492fe8b05414cbd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:1d5855d15d4c82af743bde972b42135765fe556e001a87a6d611e7aedd1dc916
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:c66fc8ebaec6d6b7aac64de2c929d0c1c5f8c39845b3821bbaa701adac4f0803
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:ee9eb35d6b636927ddfdf20a1d6149271a0634b710155ce33fbb392acc0de3d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:cd0dc237640745209b668c3ffd22bd9122cb3dfb857aed7614df64d1d210029e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:3082ea71f12bee22e226134795d831d4176c01dd0154411e9d726c9ee5561f47
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:142f8d23b02f7493cacfa986658fd45eeb7bea8cadc9ae751b62076aa92f1fce
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:3c296bc11d6596acbb9c0575a0d7aabd90877b775f75fcd8f5ca24245eae11a5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:3d06784d6cb3f3d7f9fbdf309741030d054454b5e8f0bf903cd53c18f7c56bb8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:00af6be98c976af1e20a8fb2e413371f0392ff9472858025c01fbaa9cfa1d55b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:b7da1ff323f148802a80f047d2bb9ac14e724b20b5e6ff570e347cee49ce1b58
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:db5c81a0955aa018e204326f43bdb4bdfb0192b0d5b41b255ca3935f4d0aeb08
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:3d3ae9e820d225dc3f1772eab437f0e8a6152b6a4a8c09be6566de88cbf90a4f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:7c05acf73888c168cf9939dcfcd090a5d25ae4d81a1de2aca4ab023c4e17e02e