Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 18.11.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.11-debian-fips, 18.11-debian13-fips, 18.11-fips, 18.11.12-debian-fips, 18.11.12-debian13-fips, 18.11.12-fips

Index digest:

sha256:f172a91748047925dfe171c28ec2d5ddd05db9e8a3d84fd45bf8171567a96122

Manifest digest:

sha256:67e9427fada53e4038622c04236654a7f5670a56d2c4b64f272e271d2fd2eedb

Size

445.32 MB

Last pushed

13 hours ago

Vulnerabilities

0
7
14
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:0d7b608924173ae1368cfc496e43faf7bdb2005ba75eff2574ba5295bd33e653
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:16d6d8b0a7a999b368506be6bd36cd50f3687d64ea24fec06723ade64fa96b80
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-toolbox@sha256:4b244fefc47aa29975f4852cadb716e2516e07cd1dee8056e65bf106517d777c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:46d4860eb21f315bbec75cc54201fde7ec8cdcae755b72bc1c5820e13d0a85da
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-toolbox@sha256:581d286f0174ead95e272161dc08a5a10bdb484fcf2fba1ce5b3cf8c0577baff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:f2988a50d30e5e22fa79470e20062abf287fdb64e8705ca155a5149b7c7ba4e1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:570d5b4fd359046388926ce83d2e1e2f101dbdb0e90fc1f5a7d49c12b3a9a5ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:5136dc2b05d4f486aa7a2bb90d0119ba629b8c2e8e325e592677e4f15585c394
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:9598086a2db788f6593e40e206d99f3202135770f6765ae605bf3a28fc443807
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:b935f1cf7dbea2fe7088c9ed616d1420883f8269b4d2b046e4b765e6fa13d91a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:6d57b123df6d780bc9678a8358df1f0b5f7dd90a1af040c7d4d0a7bd3a2b2fb2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:9b6c31dee201a406f5878e408b5023d102f6de8ac25ee62599f4e55389c2e7b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:44a74d92c18a71f397aa570be9bd23f45085f2d80a73d99d02fd8dc6485a7cd5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:8629a6d8179f094042f5ba271e59de8aacf0d3d122873b0c70362503ee45b252
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:2a49d2449e92fa9c0e6b7f11b157f157fc51bc37c40486ea971e4041aba57dca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:9e048788a7f7f4b726820750a0ccf89b6cbfdccf29ca0bd27538f326823e16d7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:ef77cd6a05142ec85dafa7df9d27cca6c8a1abb1ba6429668c62b9fadddf9a2f