dhi.io/gitlab-toolbox
19-debian-dev, 19-debian13-dev, 19-dev, 19.1-debian-dev, 19.1-debian13-dev, 19.1-dev, 19.1.8-debian-dev, 19.1.8-debian13-dev, 19.1.8-dev
sha256:e4641e557b2abdd58c23ac6fddaa125e86244d8285099ea4a561bd66217c6316
Manifest digest:sha256:f65810c458a49cc0eb5698c5b0b04c9246213a0b01f4ee75f6c48c3daec1a966
Size
526.06 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-toolbox:19-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-toolbox:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-toolbox@sha256:167e3a0dfd3ec535df4577cac3fe229dfe650fadd1a2a650a9c67a6a6e30b470 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-toolbox@sha256:cad73463ea53bd4b993d0aa0a6717dbd1554ed490097137551cc1ae5720cf75d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-toolbox@sha256:01fa93e7bf57fc40590069a75b7a610c9c313404d88bb28eac7476a998a47215 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-toolbox@sha256:e6e033da8b62ac378c7e1725cac97697e1cd568162799beddab1b787222f53ac |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-toolbox@sha256:cb142f2814d350555ffd7a6676ad1a223cfd110cd1d8b87e447f37643eca8a5f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-toolbox@sha256:31ed4379e7cec21f4d7effe8a3d8fc936a47e567eb6ce854a31fc692f4aa8ee6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-toolbox@sha256:dc949852235e00069d0ba43bcdd9ff92f2b44ca4f5f87e16811c3094b7d2c259 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-toolbox@sha256:03e8a86eff88b272490e9b1a92a5d46635e3300de55451bdec71b411611ef376 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-toolbox@sha256:69472a9ef9f989ec897b54ca2f070438998c96c4b3eebd4ed94c1cf94cef38b7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-toolbox@sha256:76596468e3f165925a4165eb38308142197d13c8050ba52c2b8a0b11cc50236c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-toolbox@sha256:b819348891e6671e77c25d78d42bf531a1669aaa75f0db19b577933c9e2c09e9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-toolbox@sha256:2561468f4685b155610ec50404e714ec9d79d44ec5e6187d148643d48c052efb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-toolbox@sha256:a3f2139cdf6d2181fc5bcf16dad0030b619fbd5730d153b20684ee8771435e0a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-toolbox@sha256:2fb99447ebac96cafe75f319979f1d6316efa49ec2ee64e2eb8dcfcf892b801e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-toolbox@sha256:f6141b1cd466016305113111e4cff85c414d6711b7a2f72c9c3582f164626860 |