Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 18.11.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.12-debian-fips-dev, 18.11.12-debian13-fips-dev, 18.11.12-fips-dev

Index digest:

sha256:9fc7074e383e6587b5fdd858760e0f4a64b6d67057ce630e906e0b5c1a8bb9d8

Manifest digest:

sha256:dd629348a4d74ec7dbb89401d46d418a345b849c8fb6bcd49288a1d6b9573bb5

Size

538.32 MB

Last pushed

5 hours ago

Vulnerabilities

0
8
16
13
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:e5d2a4485ab3bfef8e5a5b17e96b3f1bba698c5f120e614b5708d0635402a933
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:8c13cc03adb074e54037023a375d79cf6958cb08d690282349587fabbfdefff5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-toolbox@sha256:d31ebf07e52d3e3c4ff01456952276d70dcedd9c5f05858a3cf7f73c40025fb7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:8077f665a43d574d68d7d6eeb035e57b9e90925ca298d53c8039a71bc7a802df
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-toolbox@sha256:5eabcd2d65ac1b9115458d6a931e8bfbc07ba0765c5fc29122b15b70ef541261
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:f08da64f16b0e0a09c3c75116604a989fd824b8af828fd712bee77d1f2b90964
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:94f7b8cbc4a7252dd7a678a5fdcd038abc2b10ef67dab3d5722fe0c0c62eed6a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:295c2ce8fb48683f6dc5c5d030961af3a251005706abab77971c08c9228f5bd1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:682fefe1a72c3d30999eba6dc4df3be72894203fe0b2cadf97fc42b241dfc252
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:5dd4b3ea32b4cfbf46c4f719d5b5bf251f1020cebc3a1c02404492d1901f4e1f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:dd684c4f1e0f1be168ab399d6691a1e5ca0f224231a9a7982a57dbfce994b67b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:12186911c65563a562b5e869da619650dbab5e2a0919ba2b0e10a276fdd15c39
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:b8bbcdb40548e573a3aa9593b5f10e2db6044c04730b0a3da3c9b083037fd158
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:8ef9ae9275fa518f2501b5df4d968e29665c44dea119ecefdf42e93fb11c56bd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:1ca313bedf0b46febc716f9c3890e91be019edbc105ac84ea660eeb731f05428
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:560704ca7af2fbd6ce1999d120591c6c18634bee37813d59c75693427952b9c5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:b8966f940b268b02d6361bcf877b980f66639149df6cac144837ac8969370755