Sign inSign up
GitLab Workhorse

dhi.io/gitlab-workhorse

GitLab Workhorse 19.1.x

CIS
linux/amd64
alpine 3.24
Tags:

19-alpine, 19-alpine3.24, 19.1-alpine, 19.1-alpine3.24, 19.1.8-alpine, 19.1.8-alpine3.24

Index digest:

sha256:96aa87b2e1b20b4408229edbb733c5f9e6343ee5a5edd4ec7b41b773259d29f5

Manifest digest:

sha256:f8dbba25d452399de709cb6136bdeb34b7202ce79146136178e3e487dd6c793b

Size

304.83 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-workhorse:19-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-workhorse:19-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-workhorse@sha256:15973f796f6cc4804b7647b36946dd9f3ba5416bc261757042d01c9b9f9fb2c9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-workhorse@sha256:47fca47586a3e610c0147d0bd72f02fe887327f3452f0899e6a54d309a1da09d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-workhorse@sha256:b6b7b552726bd055c301e53cae66402169f58891454956a06b83d1e564cef76c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-workhorse@sha256:ba7e8dd7787a518da7133b9d9eab0050a0e9771ac1900d952b47bac79279cf49
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-workhorse@sha256:2122111ed843b47a151f9aa179cb4683f2d74d86ae11705f30e63c95315aa993
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-workhorse@sha256:1794834fc3e149fdae2b1ecbe9af2f23f28d63aa516a33464c8fa35dbdf70329
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-workhorse@sha256:b5679b3d593062c437c223756bf3141e390e0b87b0e89435d11ff6af64625f07
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-workhorse@sha256:49c0be3f88721d7307f558531cc32d8f1e7f57363474b2b6cca6c3002d173b23
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-workhorse@sha256:667a6420a38bfb02ef79155647a5af1a7b4584326dbd6f4785ff69eed36b3657
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-workhorse@sha256:ccaf5674d38077451a6823569991bb20d201c987926f78b566194014817b52cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-workhorse@sha256:adf25859381fabb6d4557f90efd0639a4986dd7ce7fb46eff4971d07363db243
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-workhorse@sha256:3441aec57bce5244e46fd2f1c986105f0dd6532eb60c52550cca1671d4cfa4f7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-workhorse@sha256:581ae365ebc4055bfc30cc6f4ed80849859a6d5f06746ddba5d98d88d407ef6e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-workhorse@sha256:c72bfaacf59a64485a12d0dde3468820c7a6ca53036d736bfa43db0ed1f24f6d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-workhorse@sha256:b2f577860bd5634b239c1f494112d6db8e8130e1c66e98fb68dcbf86e45cf5c5