Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.1-debian-dev, 19.1-debian13-dev, 19.1-dev, 19.1.8-debian-dev, 19.1.8-debian13-dev, 19.1.8-dev

Index digest:

sha256:e4641e557b2abdd58c23ac6fddaa125e86244d8285099ea4a561bd66217c6316

Manifest digest:

sha256:f65810c458a49cc0eb5698c5b0b04c9246213a0b01f4ee75f6c48c3daec1a966

Size

526.06 MB

Last pushed

8 hours ago

Vulnerabilities

0
8
15
9
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:167e3a0dfd3ec535df4577cac3fe229dfe650fadd1a2a650a9c67a6a6e30b470
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:cad73463ea53bd4b993d0aa0a6717dbd1554ed490097137551cc1ae5720cf75d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:01fa93e7bf57fc40590069a75b7a610c9c313404d88bb28eac7476a998a47215
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:e6e033da8b62ac378c7e1725cac97697e1cd568162799beddab1b787222f53ac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:cb142f2814d350555ffd7a6676ad1a223cfd110cd1d8b87e447f37643eca8a5f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:31ed4379e7cec21f4d7effe8a3d8fc936a47e567eb6ce854a31fc692f4aa8ee6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:dc949852235e00069d0ba43bcdd9ff92f2b44ca4f5f87e16811c3094b7d2c259
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:03e8a86eff88b272490e9b1a92a5d46635e3300de55451bdec71b411611ef376
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:69472a9ef9f989ec897b54ca2f070438998c96c4b3eebd4ed94c1cf94cef38b7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:76596468e3f165925a4165eb38308142197d13c8050ba52c2b8a0b11cc50236c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:b819348891e6671e77c25d78d42bf531a1669aaa75f0db19b577933c9e2c09e9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:2561468f4685b155610ec50404e714ec9d79d44ec5e6187d148643d48c052efb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:a3f2139cdf6d2181fc5bcf16dad0030b619fbd5730d153b20684ee8771435e0a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:2fb99447ebac96cafe75f319979f1d6316efa49ec2ee64e2eb8dcfcf892b801e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:f6141b1cd466016305113111e4cff85c414d6711b7a2f72c9c3582f164626860