Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips-dev, 19-debian13-fips-dev, 19-fips-dev, 19.1-debian-fips-dev, 19.1-debian13-fips-dev, 19.1-fips-dev, 19.1.8-debian-fips-dev, 19.1.8-debian13-fips-dev, 19.1.8-fips-dev

Index digest:

sha256:c604296f03406bd77e1ca34bfda494e05be705dbcbce0844881144fc29dfd31b

Manifest digest:

sha256:6c588bc2ff15a30668137676e96cf25785014e51d374096e9afd2059979fdb41

Size

526.99 MB

Last pushed

6 hours ago

Vulnerabilities

3
14
12
6
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:dffbaa3c5c012f2073ea0bf22234c307da347975095a2c2a6b590cc06eef27c7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:a4e9119b8f018391f9dd12eb8454d858fc38a37b2957215f32beb07019916e5b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-toolbox@sha256:743c1f0a01240def632a709f96b76c64b44fe7a2c3ba7ffcb7091073b23bb886
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:301dabb9989c3e9098ed27526e1401fff78775f820aed47228cf46d2041b5b94
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-toolbox@sha256:91c52d3e29a16068248e3f210ed69b4b7685adba2eed336a0186243386cb68d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:4ea34d440f9e20556feaa7c1ecfea811754fcac6839b10519541d26a7e7754da
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:d291b3aa1416b0e90646a9e5d51849a18f433b0360905f949e4ef01db6573562
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:2417ff9baa67cbc7cad9017293366d92c8c2779ff471b31270d1788037741d70
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:6ec5233ef72a22aedddd08eecaa68a2205e729e458669c93bfd3d9aceb98ac31
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:d0c60f0c4d5df2b2e4f54786235a5f695e5b4f3f07a5f0889da01ed6be57998f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:8afb731e2ee87c0050d6f4de6640502d0b50da17f95d3a38c63c9978353d210a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:03a044a00266233d74b28f95ea40d82ad016149252b5b65c27dcc709cdb46792
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:fa03a29b1f6f820c032597b12b28d526ad9ca284cb3986bbd5cbacfba78b2638
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:ed7b87516623517833c8627a6e968978047b2254463e6115adc3b56e3d331228
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:193fe949306787522daa536fdd35e4eafc774c6514a05befc2341fe7e47c6ddb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:cc4af4c31c8397882d0692a2eaaf345dd7c311d1d15f1eebd75af1ae4ed36101
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:0dc004ddf1a63ea1c8a46dedcaffe9017d864280add1c3a70315ced53a6452f7