Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips-dev, 19-debian13-fips-dev, 19-fips-dev, 19.1-debian-fips-dev, 19.1-debian13-fips-dev, 19.1-fips-dev, 19.1.8-debian-fips-dev, 19.1.8-debian13-fips-dev, 19.1.8-fips-dev

Index digest:

sha256:cd864171b74ea9f41eebdac3c669abf77a99b90db2e4646f2d76256355a87247

Manifest digest:

sha256:30fd0c0c0f1cf232b3d89c4beb0fb1dab91ff53627f72d269e2a98b757001baf

Size

526.62 MB

Last pushed

17 hours ago

Vulnerabilities

0
8
15
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:6132132dd0d3e66b9f4fa81309c693b8dbc4f4bddc912f5469e6c57faca1cf85
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:276a2a7e12892f76cdb6030f882d6b6014f139a7bfba2ebf0c50bebb67f6913e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-toolbox@sha256:de56b264a8c5e8e0b49b0ad96fdfd735fd268250a36b1f2195b20bdd93337919
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:d2e1212aa57eeb94d668e6024654f98bb97b0feefa3af51f35ba8c70c7c42714
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-toolbox@sha256:098a2e748251f2cb9198540301e2ef9f28c2287e7f3299f231c3f5faa0926f01
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:2cc13761ad0b03c73e4e5e4e28fe79a9d1edf85404292e175e2024956b9bcfca
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:3828011f0d49dcdca61988c588e5bbacf9eee1facbeee00d39b968cc9b5cdc25
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:74c198dfab399f5eb6395d1c6865e9e12e0ebccbe061f04c644be2429ac34043
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:b52835499a425badd5d933bc2444fdf5b7bfe5153ca432bb02ca0b4cefbdebad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:02ecd0091e2315ca073bb54ff13b745ef5eef16c3a7ff96f8844966b0f46471c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:0324263d85df1a368c41ae296f7b7d5873213ae4cc1f69d3e897c257f23086fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:ef54233f84f3fdc91227c9012eac7e0f240758cdf55efbcb1cf2a34dbee53441
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:a853f0a42639a7d32745476d29b81031676f2bc96a40906d6090567d7b56cc87
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:d40e4584794727584095f82a8e5a53d38f2cde7564875246a74d530bb1341291
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:282d6d048561d0b10c5a9150bcf05587f29cc5d38c05d0c0f7f3d5c85e7268fa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:154646cd3321931cd8af4781a4efd65e28ca0f3bb3cff6e95755fed5c118dcb8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:ca4c8fe3a7b46132bbc1e68e0621652847234a44a0b773e8777c2ad8a8bd3510