Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.1-debian-dev, 19.1-debian13-dev, 19.1-dev, 19.1.8-debian-dev, 19.1.8-debian13-dev, 19.1.8-dev

Index digest:

sha256:340ccf0b7c74823f3855a505484a9f10c5ddba7d4a4827464d6939fc77860bd3

Manifest digest:

sha256:0d78c2f32d802b54c3697e60fac2621577667355b8737b19a9f7510ea6590726

Size

526.05 MB

Last pushed

9 hours ago

Vulnerabilities

0
8
12
6
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:66a445332b3ced6bf327a9a1cdaf0640e41b5fde814a5ad8b894d97890ddeb28
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:9c7b2e833cab73da0624f0db5e8c0078c2051d56f9479df59d7aaa246545074e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:39e6864a077af035abd3b8535d49df5e9aaa8f44d605742d8bfb7ce6dc0362df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:b58a2278bcc9f4a0058b69188a709e5d2a75fd11de1212379c6893ba36374d90
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:cd29a53f10d3ed633feb0ca385079f0090c388f38170f9621133299d115b5a60
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:3c6caeb5181f9fa9733ed209b1685893174777741ad7058f43ae5b702070c98d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:06a743fb552359bb0e1a9d9044fdf534520ad7f644b14de832d5930794243777
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:318f9263ba05b5987961c278de9499e74f9fd01273a056abe32f5e493338fb72
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:7ae59a3a01898a24384ea71ecd458b6d3870ad1384300f193289922410420b6a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:e802a0118b799523a02b033c0aad2c2231128b70498e47ff4e22d4df580b25e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:9fc691c0befd1efe7d1b0d88721ddc82065217684d66bfb965a36eedd3eec3a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:56bf1caa3d51bf8f2abc4406a41760b319f166c286717aa2fc8cb1d4647bf424
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:6b136455191071b3b3661ac55c657a291512d921ffb29281b0939d7608ecee64
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:81f13e7f8594727c9f77c364b48c7fdf26a332c5b6c6bf36afd20e51ed5c31e6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:03950dc8ac62114d52760c5eee9a9dbe9ee3553eef4ce91021db1a4c685f6781