Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 18.11.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.11, 18.11-debian, 18.11-debian13, 18.11.11, 18.11.11-debian, 18.11.11-debian13

Index digest:

sha256:9d4308252c3e23e3c16b49e024983419294068110c999afc12ed8664018e47b5

Manifest digest:

sha256:e9a525be0fcb4bb133f09f33ad9a015e6316007fed64c0c5681f655645c51525

Size

583.01 MB

Last pushed

53 minutes ago

Vulnerabilities

0
2
9
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:ee21a24e4be3a7c6880a84d9fde229bd2d74edc927713a77fa2719ec6d3720b5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:6e8da88ce6019e6f83575ab96606179f66c3d01facde34395d39daab23125b65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:68d9566999f8b5eed9bb84cb66a8c717dddabe48c45782d813170a9de2dd349f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:64d2792728561c24254c36ad80abff2cbca38489a22eeb4c2cfc58a3a1fbd916
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:715107e826f35fde6141dc70b505f9fa9b656eaded854ca17343a118f4961c68
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:5ce19680f4d5f373fb11e801689a8a3c8d7d0b1f32423a93629e84a8c28592cc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:4c583ccfe4fc4b3e0accdad26dfc71ed9fe173f13e146963539206a0107172e9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:a4d9f77d2a6a9e99fb4a66d2b6c8ac01fed2833862e920347aa4e5e663a1d4d4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:cd8d3fe0998f4a4febec97efd4edb80acab47e7be1f861b9c99b8cb940b9ff66
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:eb17d394601940decb557d9443e3dc099bb80f2370b87173c6d9e48778f517c5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:9a13a12105c2c62d92e61d5777ffbb2d8300f6afe7fed0deadc6bfeb7014cf2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:cfcfd8ec44d87010dac71d46cb42bc06f6e2214f721643c57e9a9110568d69bb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:3766b3ecf117360fa0b411b21272670dbd3b8d482b88736d2de243915c7777b5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:9c08527afd98d2f50f7bfa3058205f412f6f7c1746ed60bafea55975606ac428
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:af1c16851e3a159c6cc8e0f3ad9b8e04ed5583d15bcc8b090cdd79fc879e3bc0