dhi.io/gitlab-toolbox
19-debian-dev, 19-debian13-dev, 19-dev, 19.1-debian-dev, 19.1-debian13-dev, 19.1-dev, 19.1.8-debian-dev, 19.1.8-debian13-dev, 19.1.8-dev
sha256:8c0d3b01ebe8c103b2cbd91d18131eab0c058a20df4ef0022dc8abb85759e3a4
Manifest digest:sha256:1fbaa163e3e1758ae220eb944a9108e7623b09b6082a19ab572450f5804a565f
Size
525.91 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-toolbox:19-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-toolbox:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-toolbox@sha256:90c6db9ac45c6b704d859e179827dc99d47507fae2990a7110ea6da2a12cf59f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-toolbox@sha256:a1878f8fcd58dc0fd0e422f6827674df4c2325f90856736b269fd331ae4ac7b1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-toolbox@sha256:6367f7feff0fb68f018d14c9aee118ec89de6c0e367b2158fa320441c8837cd0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-toolbox@sha256:f615bad68a70f479e828a660f55ed14f0274bae37ed90b48fc47b0263c53e50f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-toolbox@sha256:f13b76b11d715f868708288c41271fac41457c395cea3e00edfbc7fdeb22da21 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-toolbox@sha256:4feea5d5b60b6b4869fd9ceb436bd0e465d957070192d82e124525f53a46e80e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-toolbox@sha256:6f0c73c0ab5a195cb2d25f8635fa38c432fd4c1f353437a4f0f722141673eb82 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-toolbox@sha256:20c2d3ad3d9ed3657243a01c84604ee1b5783d77c3de7e62fc1e437dfed84a2e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-toolbox@sha256:e9385acb787b68744202367bee95134f562d486fe23f813a8812b51c1cc2c0e2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-toolbox@sha256:ba0ce772d3d1358555bab1c23c8eab5aa4f9339a0f48d9de9ce4be9df920498c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-toolbox@sha256:d7de6a59f23993671765a2ce16f4bf2a4447bbb484fafa270332e55f97938a13 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-toolbox@sha256:86562d7ac4c10611bbc2f52ab36ac2e31f6b5657314e47f26b6c5fee2478ecd5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-toolbox@sha256:a76580e6f9801d94ba409716e2f4d2f5077fe386826c744effe8b3764f5af306 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-toolbox@sha256:6ddca77877d5aa9b35c301e71eb89dc3232d429d1b61934f34969b30b1f3d0ee |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-toolbox@sha256:edb69540bd54377e21e0861ccd5f59da887e8462b71c85b66554675793b49c59 |