dhi.io/gitlab-toolbox
19-debian-fips-dev, 19-debian13-fips-dev, 19-fips-dev, 19.1-debian-fips-dev, 19.1-debian13-fips-dev, 19.1-fips-dev, 19.1.8-debian-fips-dev, 19.1.8-debian13-fips-dev, 19.1.8-fips-dev
sha256:c604296f03406bd77e1ca34bfda494e05be705dbcbce0844881144fc29dfd31b
Manifest digest:sha256:6c588bc2ff15a30668137676e96cf25785014e51d374096e9afd2059979fdb41
Size
526.99 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-toolbox:19-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-toolbox:19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-toolbox@sha256:dffbaa3c5c012f2073ea0bf22234c307da347975095a2c2a6b590cc06eef27c7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-toolbox@sha256:a4e9119b8f018391f9dd12eb8454d858fc38a37b2957215f32beb07019916e5b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-toolbox@sha256:743c1f0a01240def632a709f96b76c64b44fe7a2c3ba7ffcb7091073b23bb886 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-toolbox@sha256:301dabb9989c3e9098ed27526e1401fff78775f820aed47228cf46d2041b5b94 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-toolbox@sha256:91c52d3e29a16068248e3f210ed69b4b7685adba2eed336a0186243386cb68d6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-toolbox@sha256:4ea34d440f9e20556feaa7c1ecfea811754fcac6839b10519541d26a7e7754da |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-toolbox@sha256:d291b3aa1416b0e90646a9e5d51849a18f433b0360905f949e4ef01db6573562 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-toolbox@sha256:2417ff9baa67cbc7cad9017293366d92c8c2779ff471b31270d1788037741d70 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-toolbox@sha256:6ec5233ef72a22aedddd08eecaa68a2205e729e458669c93bfd3d9aceb98ac31 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-toolbox@sha256:d0c60f0c4d5df2b2e4f54786235a5f695e5b4f3f07a5f0889da01ed6be57998f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-toolbox@sha256:8afb731e2ee87c0050d6f4de6640502d0b50da17f95d3a38c63c9978353d210a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-toolbox@sha256:03a044a00266233d74b28f95ea40d82ad016149252b5b65c27dcc709cdb46792 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-toolbox@sha256:fa03a29b1f6f820c032597b12b28d526ad9ca284cb3986bbd5cbacfba78b2638 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-toolbox@sha256:ed7b87516623517833c8627a6e968978047b2254463e6115adc3b56e3d331228 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-toolbox@sha256:193fe949306787522daa536fdd35e4eafc774c6514a05befc2341fe7e47c6ddb |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-toolbox@sha256:cc4af4c31c8397882d0692a2eaaf345dd7c311d1d15f1eebd75af1ae4ed36101 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-toolbox@sha256:0dc004ddf1a63ea1c8a46dedcaffe9017d864280add1c3a70315ced53a6452f7 |