Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips, 19-debian13-fips, 19-fips, 19.1-debian-fips, 19.1-debian13-fips, 19.1-fips, 19.1.8-debian-fips, 19.1.8-debian13-fips, 19.1.8-fips

Index digest:

sha256:c147715e9bb08afe070ef789271b60ea4fe4d3ed086367fbfc63d0768f2682ee

Manifest digest:

sha256:4db4d73ab5185ba24f0896080d93e942d2773a367b8c9ce1a4e4bea35cd89d41

Size

433.73 MB

Last pushed

7 hours ago

Vulnerabilities

0
8
15
8
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:385e1024c7ab8144b2afea8e4d54afb484c6b09a134532e69bcb8c3a8904801b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:8e6e5d549853fc4374f2f369453ce52b490e1c1b00db33fcba13ebefd607c464
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-toolbox@sha256:636e6b34ac831d68f6e33c9089c45d3ddbc582115d764b6b94eb48ea1104db82
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:4840b8e99c71e160781f7710dace4e5134cd02c50a1c7fc307536aa7a4c0b6a2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-toolbox@sha256:a008bd4d098d58d36c35ed2dec315057f5fa8251e2e4fd9171d7e514157d4e62
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:b874e63351e34987a0ed4a114616e9db4bf9c8180eb31980baa947a3539e53e6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:924c0a75b4f15f87e5cc4619489b947886d06ed6f6c355f05529bb788c8c64fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:3d4e4646ff47f64bd255df699ef3b66273cdcbff429c46252fccc3e0f7f2b189
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:718dfeb95e7b9f7d898d54ef31a6825c9a58cb2ad1c2a8050e631034dbfc04b0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:0075c29de34359c9a7449312b3ca858c426868f3381305cf83211f4126653841
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:3e2b12d38e32d5ca5d6f5d27c3953e3487f36dde817b27dd700ecabf030406c0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:024e1d3b420ef1df7fb52af63e413306b8ef37ea8576f4d4fe4472ee4d1d3050
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:52ae4691c35dbdc4212c8fb968018f44aafd4c5c34c29f70ea97e5c72675b2cb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:0b9d292b588eae206de0038126585d2a737a54265b8db674f4437a512f219c23
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:154a87dba27bd78d3196c6017bcb88672d0c5cb0c55f44bfdf76bdedae017812
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:90da049b38f9546f36d87d441807f930b7555ce81f00102926f99a5370958fa3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:fc3a8dad9ab4f5bc44f91232239e3f8fa108414ce53a4a741152bdab54526dd4