dhi.io/gitlab-toolbox
19-debian-dev, 19-debian13-dev, 19-dev, 19.1-debian-dev, 19.1-debian13-dev, 19.1-dev, 19.1.8-debian-dev, 19.1.8-debian13-dev, 19.1.8-dev
sha256:340ccf0b7c74823f3855a505484a9f10c5ddba7d4a4827464d6939fc77860bd3
Manifest digest:sha256:0d78c2f32d802b54c3697e60fac2621577667355b8737b19a9f7510ea6590726
Size
526.05 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-toolbox:19-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-toolbox:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-toolbox@sha256:66a445332b3ced6bf327a9a1cdaf0640e41b5fde814a5ad8b894d97890ddeb28 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-toolbox@sha256:9c7b2e833cab73da0624f0db5e8c0078c2051d56f9479df59d7aaa246545074e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-toolbox@sha256:39e6864a077af035abd3b8535d49df5e9aaa8f44d605742d8bfb7ce6dc0362df |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-toolbox@sha256:b58a2278bcc9f4a0058b69188a709e5d2a75fd11de1212379c6893ba36374d90 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-toolbox@sha256:cd29a53f10d3ed633feb0ca385079f0090c388f38170f9621133299d115b5a60 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-toolbox@sha256:3c6caeb5181f9fa9733ed209b1685893174777741ad7058f43ae5b702070c98d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-toolbox@sha256:06a743fb552359bb0e1a9d9044fdf534520ad7f644b14de832d5930794243777 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-toolbox@sha256:318f9263ba05b5987961c278de9499e74f9fd01273a056abe32f5e493338fb72 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-toolbox@sha256:7ae59a3a01898a24384ea71ecd458b6d3870ad1384300f193289922410420b6a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-toolbox@sha256:e802a0118b799523a02b033c0aad2c2231128b70498e47ff4e22d4df580b25e6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-toolbox@sha256:9fc691c0befd1efe7d1b0d88721ddc82065217684d66bfb965a36eedd3eec3a4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-toolbox@sha256:56bf1caa3d51bf8f2abc4406a41760b319f166c286717aa2fc8cb1d4647bf424 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-toolbox@sha256:6b136455191071b3b3661ac55c657a291512d921ffb29281b0939d7608ecee64 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-toolbox@sha256:81f13e7f8594727c9f77c364b48c7fdf26a332c5b6c6bf36afd20e51ed5c31e6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-toolbox@sha256:03950dc8ac62114d52760c5eee9a9dbe9ee3553eef4ce91021db1a4c685f6781 |