Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips-dev, 19-debian13-fips-dev, 19-fips-dev, 19.1-debian-fips-dev, 19.1-debian13-fips-dev, 19.1-fips-dev, 19.1.8-debian-fips-dev, 19.1.8-debian13-fips-dev, 19.1.8-fips-dev

Index digest:

sha256:24473cca77def1f8bbb8b0cc1e72c8251d0872b2032b5cbcb6466c45ccf30f0f

Manifest digest:

sha256:0847267c6c86b9686cbc273386bbac843cc585adf04cc70bdcef65e566f5a864

Size

526.56 MB

Last pushed

11 hours ago

Vulnerabilities

0
8
12
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:9d2510f1784787d4a14de961c5ed7c9c3bddaaf94b865ae3146bbc59f5687380
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:9762128e84734d8cbcd6ed7662f8b86da9388f662bdf3ed440bb34742eb47c6f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-toolbox@sha256:45bd18c5744795bc1c85f0896152e98843e8f2e7c6ec60521de325cf7ad336a5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:01b2aa1e7c237af287a452fb4b01c58f6b46ba3f6d66395ac96da9de0b96eb1b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-toolbox@sha256:d0f629a6582e81f5c3821979ca449712a7fd76515ee5ad451694b1fbba833434
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:298653d1918e544369bb174ead635361b7486c2d63ed96e132702be1a3a1c8e9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:bd0bcefd00b008a9cd0129316eeccf26c3d33f1067129aeadfafc06875517dc1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:43bd01098a9c8b1a76b08f1993f7fa08f0abb62c841023f5da56a64a3a461095
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:b8637b22ec58ff0379c93f9a9d9cfdb1930be3283b798ffe35a3bb104c7c1cb9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:4f586557607792c2bfe09aa18ac2daa2613c52e81a5a5b60e917b91d15654ebc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:08379935daa7c22d27411e769652d264a22fcd0eed7e17dec7d3c3a15f9e37a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:22f8e89411046642862c859c69f68b9421de978c350505acda5f62b6be8c58a9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:d260b02ca0208f485fbca0ad382ae05ac01fc4c56f2dc54c80526fad58c14194
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:398ae105407130da409e6934e59ab4066450f0ec1e25030b845bba404bad0568
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:afe142a204fd70dd37a8c37cb4c5065b63b94dc1a236a931ff81cada586b6d87
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:bdf11d4a8735f015d6c7d241df729c8c58af55049f09e2b28760dd56df57c423
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:310c5a155c56e8b8cef5b6ec51ac864a502847129c47c039720d8a8111733600