Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.1, 19.1-debian, 19.1-debian13, 19.1.8, 19.1.8-debian, 19.1.8-debian13

Index digest:

sha256:b7e5ab8fc9e821101768c5f3381213b6b582705dbb6268cb67bac3bb5387cf4a

Manifest digest:

sha256:1ab8a18b95694085980767649ee2facda03a9e0d18a096731b19f50b0973822d

Size

432.95 MB

Last pushed

10 hours ago

Vulnerabilities

0
7
12
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:dddb8c29880c726d47582ec9a3349cba118841663d408f534332ff27cfe0b59e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:18d7f98baa84e2e6c83aa130b6c1ede3d2b34341268e31df2c5d6db0ac1d3acd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:a3cc40f8af7857168ecc46baf11fc296d683004e141d9eca3c159846da7d54ba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:0962149087820d256ab61b18e0706603a1b7783fd2ff8be0f1617036f38684ed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:875ee57515fc1fd094eeee6d5a5e7b4fbbab806b2c95fea1310a0cb64405c042
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:d7860ba66b43e09822928f865f0bab89c26d83cfce12d0b73ef48ca8a7a4b8e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:fbb505ddaed4f33224df936218071a059f60db372b5a87b0f48e72fd53236655
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:82aed6cde1245a8190bee86f454fdf75381b4b2c35a1ddb14d834bad3b4cd98f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:d91a3c21c87d3daac270b64f453f1186b49c7f636ac4c53e884b09d5b117c500
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:e966d37fb61323ed1e5d089a2a7023f00546d892ed7a1786fb51de9778095e2a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:9ceaf4b34a4aabe61f4fd2f071de1f98d96882e7b7ec3245da8d262e2bb73abf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:0582d0a473a6066e18bf99070796c5a7f4681d5a398c7cef12fee750227c18ce
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:0abcd7930e8dd4ff3e645641828d184ac4c4342c6e7c8edff2cc721b834a20aa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:a7def3e8f789a6552db556952256bf131de3c7409634524d8a2bf39f306d691c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:66d07b0d465669ed49e530ddf6fa1bc8725f7cface52cb95bbfe288692c51717