Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 18.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.11-debian-dev, 18.11-debian13-dev, 18.11-dev, 18.11.11-debian-dev, 18.11.11-debian13-dev, 18.11.11-dev

Index digest:

sha256:65e640aa2983a14c00202d038121250f4de25c2910883dc3a421a6b1942b5100

Manifest digest:

sha256:3b9bd11a8df31754046f13cbf0bb36726b51c9e094fdf1706667b4577c422eec

Size

665.64 MB

Last pushed

11 hours ago

Vulnerabilities

0
4
10
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:df50771ba84937adc9575f2c52b05f3bb066dff5e116a7db732df7e78623257f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:ae84c47bb93669e9630686afbd7c257abc07c64612c64b7354d14d6558181948
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:2f3691a750cef75f44c7f8804f280441c8a02a8d8df5d908804d10c22a2989a6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:c264d266482014cf8054ec0647cc3df33be428c646e77b433bf12c5f82e5f8cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:67b2306ad35276b696ab4c730469cd0c4463bdada9ef2c698441020fbecb422e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:f396bfdfca7f8509f97f63965a6fbad63e17da927f84966cd4357ff91a005329
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:573543bf433aece68c015f7e82c99058df2f670d8cdaca4db5b9e596826714b0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:68b6f76e4075006b882425211899f335c35832f17d5ea89c889b1bca2d67307e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:66306c2d68412b1f9fdaaec020df7e0454608289d1b4da3e57fe4d186a7b7dfb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:bea1021d58dcdf064e82582eb1a8fb1169d2048c1d7487fa924dbcd6d8daba9b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:1d3f2004d4e8a30abcb10fee7ac22bc714b50a2f7e6dc7f36f3ec553b74b08f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:eeea00308d8d3c7a0b4df77f091c5e4116978c1c00dd4bb48a43c3b814a2951f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:53580c1058b2b8b0354ce21317c6841c2ca50c59d2dfbbef893ce0fec676c1ee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:c31640e7aebdc2e49a98da013676ecdb78e0acc892c4b700d47a0779a97d0bec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:15c3464cc9f09081ceef25418c429c79af7bec02c8cde51c880e7af44b8d4064