dhi.io/gitlab-toolbox
18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.12-debian-fips-dev, 18.11.12-debian13-fips-dev, 18.11.12-fips-dev
sha256:c7e49784dcbdb88f80107477b1fe2706bcd56180f504ffc54dd2708d717ce7e3
Manifest digest:sha256:24e1dbcc7ff88328de265735a46d0cd9efa5fe3cb0fc507ce0cf4bfc07b59a74
Size
538.35 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-toolbox:18-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-toolbox:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-toolbox@sha256:9c8e6a4f95ae52624a3a069396c7ade3e5dbf8745630d6c745a95ea6ae64ec03 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-toolbox@sha256:0977f35bd37cef6a450809a440017e4a51512df2a9c89a7c826f5edd442ad743 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-toolbox@sha256:4b559b99b4c54d361258ef8916cf142382b33f67c45d0f4718c562d80e7b6795 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-toolbox@sha256:384ad63aec8d405b5ac5741232510799bb5363e7d18528bad6051bee0e1d1a07 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-toolbox@sha256:74615e993f8e596776441068edcb12b39de7b2a0a727f90c76d5dbc28df8aa37 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-toolbox@sha256:afc15f5ab2f59a5448f643d1e7a8744a329f22d7c9e29ccb54dbb59ed112406d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-toolbox@sha256:7ed841b89ab785fbc68301613da2eb95fb775fdb957db8d31b91bf2c701b0002 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-toolbox@sha256:6ba0e9c6176cca9697c521e2fdf83dfebf5888e154ea7700103a5c376f5b7a91 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-toolbox@sha256:74a3e6a6e86bb833c2eaf5f3c2257e25353422f3ae8bd32414972f31b5ad4cc9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-toolbox@sha256:703ea7197fcea27c6b0134dd6cea6735601d116e82f76ee81fa1ef8e9f0a0808 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-toolbox@sha256:934568b5e07627346aa1efdcaefd7f0a903231ea33630a6fe7bf6167bb6e0ff0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-toolbox@sha256:5a76ab3d537d78ff1d851c82eb8ec41fd7f5831f2694799b055eb161ee5ea18e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-toolbox@sha256:521fa26f9dad9e8e9bad0800a8aea8d4e8738a874d05e192cf864def9398483c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-toolbox@sha256:1bcf0f517ff5ac0ea21536fc3b84c2a0b7e5f9ea8aeab79591ba32e6eed14fd6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-toolbox@sha256:94058191097baa4cc21addd992939de05a322b969dd7a62ea512565cddf38676 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-toolbox@sha256:e793c2d7093df26fcac9bbf5ae7d88d974b0957f2fdba77b4157231b3b385b7d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-toolbox@sha256:dfca791cbfd9858b7962797a6a306c1e05be11ccb3bc5b7807fbb19241475bbb |