Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.1, 19.1-debian, 19.1-debian13, 19.1.8, 19.1.8-debian, 19.1.8-debian13

Index digest:

sha256:de78080e19aeef5997bc483197ee07849a18983f50c0e32c46fbd0aee8fa715c

Manifest digest:

sha256:44444671a17be47b5928b5b507baf986698db5e1f6b095b7c27ac62f18361fce

Size

432.97 MB

Last pushed

12 hours ago

Vulnerabilities

0
8
12
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:8bd8fca25852ad4b614a15cf97ea165a6e7f1697e96c8d43bcd2471a2048d9b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:9e6260855edf041fb966ef8e26b6e779f9026869e42d674bba8536be8761c3b4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:a5046ada7ede2de4197c5cc9290ba791cbbaa5a45a723125a64310f0fcc13397
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:d984b47a5be7f1934432b45a9e2e98aeec23f72e3aaa7cfdeb55c4443c2a4936
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:e30964f86ed82414de33e16b1451ef3c5b3b2baf874ea022b601adcaec12598a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:c97fb85a9af1b73eee9b54ae5cf9b6fe68f546a22f716d0e3fc57a9d3b9f0b7c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:0b25fcc05bea3d64b188200d6ed8912592d4345d4ac38fff2024e23e92c069df
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:b44b8f63feb432c1cb9f5e3c645c48a96bc77621daeea45a520ffdc643240b0c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:48c98d60bca7a0cb7a5b1eba2cae888ce8e92bd81d1965df251f56ea914ec3e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:fb9fecfc9a69b67dc34cbc65c090ba2b4c6a9968eca67360b0953cfaf877c71f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:ced00ce05adc765f2d6f894797ed69fbe912396569fc183e6aa67f6753ad931b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:419422bb1d5662f080b63ed1428178e6e4f3cf665d7be62b3320e2ff3a626fe3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:48e0e119e055d0888ea94579902e4dccd546c8650aeaad0aa32cf49353366563
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:9a8e4cbc0d685a82c1313f05053727776a19007358e09fa9a6ee744600d6e3d5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:ced52c1a414602bda717350735ec28aad089af5bc1b1ab78e7f351d7040c5f40