Sign inSign up
GitLab Toolbox

dhi.io/gitlab-toolbox

GitLab Toolbox 19.1.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.1, 19.1-debian, 19.1-debian13, 19.1.8, 19.1.8-debian, 19.1.8-debian13

Index digest:

sha256:8f781fdd9bca3a26e5ebde3b1927442bba6cff12cc7e78f2a37ab99793a0a80e

Manifest digest:

sha256:9cea4e0552348347fd0aebd77417b3f8c9c0beaa6d034523e086869c31844d6f

Size

432.96 MB

Last pushed

4 hours ago

Vulnerabilities

0
8
12
5
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-toolbox:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-toolbox:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-toolbox@sha256:fd81b2a56edab42b00432e6447607c87872e6a474100ea433aea18eecaad4982
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-toolbox@sha256:20b47dc02b27e94830f73ef0d4d9d613046c0917b2f2c49fc27788e7c66ce3e4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-toolbox@sha256:9da4087453b6d43b900664251d1b0842cf09aeac0e4f2b1ab47a48c5efb6b056
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-toolbox@sha256:b1d721d78f8ba3e1606dc2fde2a9b33f9e266408c57fcdd23e374f47dd700ec0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-toolbox@sha256:f58e3fc5f22d99eeef50ac2f23fba41bc332d3956cbd01f64edb4573cf3619a6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-toolbox@sha256:f646797b47ebd67ece786e8d5154f41cd57e1246e667e264a449fbb79ece8503
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-toolbox@sha256:da5e1fff3b782ed3c073246a4625d5aba4cef161a383059155e2cbdacb9dd6dd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-toolbox@sha256:1db0eef761aebaf0aac97a2b0f3aadc1db0d67a46a1b4bb382d713fe95924969
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-toolbox@sha256:ef0d5794d547396691da02ca28996db8a58a548686a44e9a2b1a984ef3016bbf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-toolbox@sha256:feeac6d66e96d2e6000a617411d85243baaa7024edd46b50b237cd76f5bda3ca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-toolbox@sha256:ba2fdc93a81f7eb43c54155a1367674ce0862864805137f7ad768f16b290d5a1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-toolbox@sha256:bb406007483dfe2d9880be4a612e2b9974e80378b01106ba77f7a853715f1151
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-toolbox@sha256:289bb06024b05b06dc2ee82b350a85a7a3c226465303b8746babd615fed9a9c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-toolbox@sha256:1087b7a9b16b390c26629604f98c012c02dba3a5bd9f2f670523115df77c346a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-toolbox@sha256:4cd09908806e6e27144de4d3972e86c0e69392e4ab370e5105947dca34807d10