Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 18.11.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.12-debian-fips-dev, 18.11.12-debian13-fips-dev, 18.11.12-fips-dev

Index digest:

sha256:cae65e7a4f88f413b65dc7be67ddd161e4ad0dae452b5d1dd86568fa38700c7d

Manifest digest:

sha256:238833fe2a2eb39bec3db6d9050e10ee73746f3a56368f2563f135a466b8f0f6

Size

538.52 MB

Last pushed

7 hours ago

Vulnerabilities

0
8
14
6
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:f841f29afa3ae27174c585c83ab1e7bbc4c14df8add4622b31426e0c6039642f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:7b234be51f89eedc3496ac558ccd175a55867a4cfcf5e1d6622ce4140cb4e421
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-toolbox@sha256:1f7b6ed347dbd41b835bedddb3cbec4aba38bbb1ef60a9983e333b7c724b2e0c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:0e2e13cfa9d12ae880d1fc572111437dfaae63ead551e0ca1519569eaabd70bb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-toolbox@sha256:cf612db43a3526d4939e29b9810b06f0e78cffaadd614cdf239732e769b1a063
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:4f5158e4c390ae6137be975bcef1e6a1189774bce3c3ef7a7616aa053003f7ce
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:20410a003236757a5669c75dec5832f40cbe3c5197a7bd42272a0e088a3aebbe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:ebaddf9dd3fb082535914c1af2363ffd9e752d71563e64af0fb16f05fcbe0ed4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:3e1925918d67b7bfc0752a48d7c4a98311435740a5396f17f46e293da1018eef
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:06879c087338972a27850c97b30dcdbdf29d5d65821d8ee106515a7de1a79076
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:0284a38ae382280f520f25c00c9e6c858b31975f5bd882c1c754bd60d4fff13c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:2944163b43d0ab2d1b62a3d4e36073c53aa5f4870a5c60348dbe8989c5970c2e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:7377e47ce51ceb0a1f8b155bf43d9633a58100fc8ff83a099d296f1041fb0366
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:db44dc1f8fcd0f99e074e87cb85d971df96bbb5eb11e3dc55a7cae237ec13feb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:421514d568afc035433b4414ac96bbc5204477e9407eb34b92d198aa07e92b19
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:d0ee402a4fd518998c5a03a0ee5d6ffab1140bd2a0ed1318b70ce5ebf8b8b26f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:27bf9e0cd5d376dc9c7b6b54688fde1906c29d9377f2e6292fa422a20f479084