dhi.io/gitlab-toolbox
19-debian-dev, 19-debian13-dev, 19-dev, 19.1-debian-dev, 19.1-debian13-dev, 19.1-dev, 19.1.8-debian-dev, 19.1.8-debian13-dev, 19.1.8-dev
sha256:95d22b699ade2a7c1528a8c0e3083632a65c34756936d2d0306e54d1bbdb4b35
Manifest digest:sha256:742530ec3788b1e0369a14a10c1ed5427b5a12d1a9e3fbe4e0b86f9edf589177
Size
525.94 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-toolbox:19-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-toolbox:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-toolbox@sha256:473955a8921793f31920d464a0373ac4029f3baf6a8fabf03654437999e0d6f0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-toolbox@sha256:1db0bdbddc19ca67ace3e691b19521bf6fded2f8505ce7e4fb492091c75739eb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-toolbox@sha256:6a12a2c6db3d44753139b000ab54343ebaf5e8f04bb29a73374ec79180fe6de4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-toolbox@sha256:05ef0f24db3d4f8961a96b905ec0a2e3f633b554b336a33906de292b5ccfc61e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-toolbox@sha256:038ceaef863787b93f6c1563edd3125840f1fd84ac6ec3ecc4a500fcf81a9fb6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-toolbox@sha256:fe87d824814088e4ea642950ef4024e2da06932e10289231c330b323aecc3f11 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-toolbox@sha256:5004401f500f8e448e577c9f6629b8bbb7b68a7f5b8de47a9aa3ad91780b2572 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-toolbox@sha256:7346aa3463e4f711e61c77a87f4fbb87f38b087630c2bb8c6525611317a29ace |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-toolbox@sha256:4c51bddbb9a7c2e518a73540d8f7996a61698f719f2cd90d4ea1c026e3856dc7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-toolbox@sha256:b58f0bc646462ac0dd7c32007589f22298abeb322f2941f3e51d8561f716ddea |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-toolbox@sha256:ee66b88c7314c414bb177815334df6e1c715a21451d15e31cb8eb74477ba061b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-toolbox@sha256:d3533ad4f7d4bb2607043e5235b3db110fb524f0d678186076193a312bc7ed58 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-toolbox@sha256:9a855b082641b04b94af62257dae4026205b14f17c3186cef936ba757cc4c023 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-toolbox@sha256:2a35059472b14158abcecb73ee02dd891dc6e11f30530bc222b1f3174ed2b936 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-toolbox@sha256:6302b4de1c998db740407ab07ccfdcba047125c0fc5022cb21517a645124515f |