Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.1, 19.1-debian, 19.1-debian13, 19.1.8, 19.1.8-debian, 19.1.8-debian13

Index digest:

sha256:c7f5393f2198650499ba1a58e9abb3e77bb7a94d338387fd7d29552a901ba73f

Manifest digest:

sha256:9bd6fff12c2ba4afaee3beb2aae0549323ecac4cd2f08cc0cfd84600b236b949

Size

432.99 MB

Last pushed

10 hours ago

Vulnerabilities

0
8
15
8
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:d036975fe78814bc37c76cc14f385f6774ff477ec97d9efb65d6f9fc85d33000
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:bda7dc6db406e89f5b0b42a43629b123751d2846b6d19fc82352b910a6492263
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:f61c142466fc154acc70cc0bddb6982b0c88206af616bcd48ce09f4972f628ba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:8dfd1215fa27b2c46d95b974f942d7a0df818396f99f260bbdf6918a38d12f54
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:33aad721cae736d663d86b68e2502723241186a79859974da6fe296898f09681
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:1b7238bf15220572c52d7f169091432e20b66b0c74b86a5cbd09a09e67312f86
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:b111543b69a50b7f537affdc316d9047fbc2b9f74a993330b1668764cb185141
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:85f87450f72ff75e030200b568d1cde2ea77732c132dc44629677b8d41a25cea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:85d845dbe93eecf42e4108dedf442f8d1eb75233b33a5bc02d865272e37500f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:928c5b90f8a8e85b0992de9e74c7e7041f7a43690a4c3815beab0f58d4fa31cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:0500e997eb2d5a7f1f9ffa4e88a73d60560f044f68599ab46f29c2ee9671078a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:8197f1e31490c7a334e478f5ff4be9ff3ea97be2ce32adc0b93976d8efd3f87e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:5b0dc262b0950fb73d3e1d76859a8b639796542d13e5f8a8d097940a9a6140dd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:e5b88e41311a14793ee3c381f243ad96d94e839c55f821842c5034ebe7cf3437
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:68d7f1a3877e4566e317d43ac1ff8f538f72f1cdc05e959fd04c52ea696827cc