Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.1, 19.1-debian, 19.1-debian13, 19.1.8, 19.1.8-debian, 19.1.8-debian13

Index digest:

sha256:c33f4bcb567d254f5e577a3ab5e98859e630c5c4959cdfc0ec59eb8e67b8f77d

Manifest digest:

sha256:7c1e556961ea85b7c60041bbd29d40759eed40f7621df9990742a9371ab33489

Size

432.84 MB

Last pushed

13 hours ago

Vulnerabilities

0
8
14
14
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:6619c52dff61fa7cad0ecb8b015315aba4180246611724946b52fe7790e852d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:9aa007a833334c88d2c54f08663bd552ae8777581bec02ec955a2b1024da337d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:e03589301eb8792095f2592bb4bad6bc3cc980f698fa9ec088bed5778e168b80
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:fc8d573c13a768274e4bfc2c077db85ce24655fd708e1d50980445a27699199f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:4967695831f717fc0243acbfd181c6afd2ccda601ea57455ac16476ea09554ca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:42ec7564ac70ce3c9f56b5820f53fda85301ab8187afcfc5f077f19b19087277
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:1e0c585dee0fa8a07529a05dc3f90f374fab4c204aabfb3c413ea2daceaadbc0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:71b90f5a1266eaf984ebab79349aa736f8fee95e2bb6fdb8fca9f20a8fa25d95
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:223f1ea78f548e74b852e06a46c921077e54416b8812f2f90412e002c92fc8a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:5f91734fcfa949dfa27453cd3771be93826c059a057e8e9adda21e52ac8abe44
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:61b54103d1c6c995ec70e3fb44ed6f6372ea4b36d73a58c31970eda5d77bfd8b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:7dd2d0ac60676a0279a70961d184ca48452a1760a8a21a77afabd93f3e34109b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:b7d35c4c1e955a6e68c1a384c02e01a7c3405cda98265f7ef27b625cbc2e916e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:7ccf72712ae5d47a6621c590aaac2c666f70ff63232eec380b7961c4a4755422
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:fae1ef7b8b874cb7db58e45896ef81a77101a2cec5e04b05853d167f89f43f3b