Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.1-debian-dev, 19.1-debian13-dev, 19.1-dev, 19.1.8-debian-dev, 19.1.8-debian13-dev, 19.1.8-dev

Index digest:

sha256:8c0d3b01ebe8c103b2cbd91d18131eab0c058a20df4ef0022dc8abb85759e3a4

Manifest digest:

sha256:1fbaa163e3e1758ae220eb944a9108e7623b09b6082a19ab572450f5804a565f

Size

525.91 MB

Last pushed

9 hours ago

Vulnerabilities

0
8
15
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:90c6db9ac45c6b704d859e179827dc99d47507fae2990a7110ea6da2a12cf59f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:a1878f8fcd58dc0fd0e422f6827674df4c2325f90856736b269fd331ae4ac7b1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:6367f7feff0fb68f018d14c9aee118ec89de6c0e367b2158fa320441c8837cd0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:f615bad68a70f479e828a660f55ed14f0274bae37ed90b48fc47b0263c53e50f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:f13b76b11d715f868708288c41271fac41457c395cea3e00edfbc7fdeb22da21
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:4feea5d5b60b6b4869fd9ceb436bd0e465d957070192d82e124525f53a46e80e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:6f0c73c0ab5a195cb2d25f8635fa38c432fd4c1f353437a4f0f722141673eb82
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:20c2d3ad3d9ed3657243a01c84604ee1b5783d77c3de7e62fc1e437dfed84a2e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:e9385acb787b68744202367bee95134f562d486fe23f813a8812b51c1cc2c0e2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:ba0ce772d3d1358555bab1c23c8eab5aa4f9339a0f48d9de9ce4be9df920498c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:d7de6a59f23993671765a2ce16f4bf2a4447bbb484fafa270332e55f97938a13
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:86562d7ac4c10611bbc2f52ab36ac2e31f6b5657314e47f26b6c5fee2478ecd5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:a76580e6f9801d94ba409716e2f4d2f5077fe386826c744effe8b3764f5af306
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:6ddca77877d5aa9b35c301e71eb89dc3232d429d1b61934f34969b30b1f3d0ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:edb69540bd54377e21e0861ccd5f59da887e8462b71c85b66554675793b49c59