Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 18.11.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.12-debian-fips-dev, 18.11.12-debian13-fips-dev, 18.11.12-fips-dev

Index digest:

sha256:44d7842fb2e6fd65cf19878e20bcfbac4be3754b081f1eb529fe7d7d392dafc3

Manifest digest:

sha256:13d5ce20e8e03e011c49287598032cfb916a1786d6defda42c46ec929bf9a646

Size

538.52 MB

Last pushed

15 hours ago

Vulnerabilities

0
7
14
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:238c1e4b0c47aa189697471098a0d5d516bbd5b3862c758a4de6758609db936a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:59b97c4385613da92e6bd1729c9eb5819cddc8dc6b48ee59b7a5cbada76a6569
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-toolbox@sha256:f01051a3ff431e2c8ef64cbfd65f7e023d2541b6ce1d71f5f8de0251b7bb2f97
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:c9ea5bb946ffbf661c52bc1d2b114ce17f993f7d39189a26be35959f5dea89c1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-toolbox@sha256:50c7fe2dc61e1e0794d0106cdcb7ddd4aa54e06ea50d31b8bb3ae83ea6b03200
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:af70e8724f93bb7c25eb872280066fbfc0e2474076276964536de201b0ee0a2c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:7a3e7dfbee70db811485ffcb8dd074a2ad278bf5f034d302400b32046098245b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:aa68ac31a13da32726f50b6fbb475032f5d261775491ccad5b5e74d51d13d756
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:939343d1b91870fb35f7dd653ab31df8901b7bf0a9a6114c60befe10930b5135
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:a5b4d52b9c42886c0a890b7a01b58a7fe3985fdc7f20127c4663a610a3ba3313
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:79a05b344f8477cdc46ad163ba61070f0466d064eab3989a6a2797596f44fd49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:8de8626b8d1aa0a71ee7ab6d591f232f502535552db56d513de64b6393c9961e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:5b0ef0c3aebadd75e5b6eb9b9745913c6924e353941bb826985b709f06991344
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:e3caf4508b322a5dbff760582fc8746fb8c6c2ec12e36e9e82b2e6b740684918
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:bc5daa4adb5236f5adbf3521130eac3e72f3fd4b4219229bc8ef6fcd4a549478
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:dd9dc2175977757f31d6f09a5c8fa6d5f510e8d220ce52cb13be4ec071b6e82d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:6e93f3019ef95409c6e9f3a7d22c1401e767c56eef0ee05c8ca811e28164164f