dhi.io/gitlab-toolbox
18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.12-debian-fips-dev, 18.11.12-debian13-fips-dev, 18.11.12-fips-dev
sha256:cae65e7a4f88f413b65dc7be67ddd161e4ad0dae452b5d1dd86568fa38700c7d
Manifest digest:sha256:238833fe2a2eb39bec3db6d9050e10ee73746f3a56368f2563f135a466b8f0f6
Size
538.52 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-toolbox:18-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-toolbox:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-toolbox@sha256:f841f29afa3ae27174c585c83ab1e7bbc4c14df8add4622b31426e0c6039642f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-toolbox@sha256:7b234be51f89eedc3496ac558ccd175a55867a4cfcf5e1d6622ce4140cb4e421 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-toolbox@sha256:1f7b6ed347dbd41b835bedddb3cbec4aba38bbb1ef60a9983e333b7c724b2e0c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-toolbox@sha256:0e2e13cfa9d12ae880d1fc572111437dfaae63ead551e0ca1519569eaabd70bb |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-toolbox@sha256:cf612db43a3526d4939e29b9810b06f0e78cffaadd614cdf239732e769b1a063 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-toolbox@sha256:4f5158e4c390ae6137be975bcef1e6a1189774bce3c3ef7a7616aa053003f7ce |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-toolbox@sha256:20410a003236757a5669c75dec5832f40cbe3c5197a7bd42272a0e088a3aebbe |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-toolbox@sha256:ebaddf9dd3fb082535914c1af2363ffd9e752d71563e64af0fb16f05fcbe0ed4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-toolbox@sha256:3e1925918d67b7bfc0752a48d7c4a98311435740a5396f17f46e293da1018eef |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-toolbox@sha256:06879c087338972a27850c97b30dcdbdf29d5d65821d8ee106515a7de1a79076 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-toolbox@sha256:0284a38ae382280f520f25c00c9e6c858b31975f5bd882c1c754bd60d4fff13c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-toolbox@sha256:2944163b43d0ab2d1b62a3d4e36073c53aa5f4870a5c60348dbe8989c5970c2e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-toolbox@sha256:7377e47ce51ceb0a1f8b155bf43d9633a58100fc8ff83a099d296f1041fb0366 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-toolbox@sha256:db44dc1f8fcd0f99e074e87cb85d971df96bbb5eb11e3dc55a7cae237ec13feb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-toolbox@sha256:421514d568afc035433b4414ac96bbc5204477e9407eb34b92d198aa07e92b19 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-toolbox@sha256:d0ee402a4fd518998c5a03a0ee5d6ffab1140bd2a0ed1318b70ce5ebf8b8b26f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-toolbox@sha256:27bf9e0cd5d376dc9c7b6b54688fde1906c29d9377f2e6292fa422a20f479084 |