dhi.io/gitlab-workhorse
19-debian-fips-dev, 19-debian13-fips-dev, 19-fips-dev, 19.1-debian-fips-dev, 19.1-debian13-fips-dev, 19.1-fips-dev, 19.1.8-debian-fips-dev, 19.1.8-debian13-fips-dev, 19.1.8-fips-dev
sha256:6a973c6194a7b1edd20fd7d61694213001434d1bbdadef182d0e9e62ea6458a3
Manifest digest:sha256:e20a96b80ed677b6f640ba694f7ae73eced2bbc40841425682ab9936d68a34f2
Size
324.91 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-workhorse:19-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-workhorse:19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-workhorse@sha256:6445a5ae5f63915d8a44fb6af7e38143ade8f245353b246e946c7606b10659dc |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-workhorse@sha256:56782fec314d359ffbf59c15dc369937deca2effce74e8780091eec0abed40f5 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-workhorse@sha256:0362bd0fc5971ebef5b1b2398f2ccbe6526d688f5cf2d642b1781d107c6feb78 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-workhorse@sha256:c3bec95a34495ff331aed1c651b43943d596e70729cbdcdeae2c02a3afa5b12c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-workhorse@sha256:db6e5622c265856d4dd1aeddba32ad03078bf0bfcd809193d072e7fe4ec29cf2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-workhorse@sha256:7d40a4da0cfcb716457a5f5bcffdef95f89c8b97913ba2d7fb08facac4090d77 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-workhorse@sha256:69851cb87a98ff9a07ffeca1a9e10519544538461fd2645223db705483163dbd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-workhorse@sha256:774a9dd477b270f017b16e77c3ad92dead476da802a02fa218bccd93aeaaff07 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-workhorse@sha256:38d97ae4ec1899552faf99c14474edacdfe16a7695989ddf5e71d40aaf61d8d0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-workhorse@sha256:98118e576b0a3c2f01b180054e9af5efed30b0a0fd4d28ebb26f766b700b09e6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-workhorse@sha256:371935f5f128e0f30c4949fa92bc9c4dc48eac244edb2776c67c36a5d8c65c05 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-workhorse@sha256:3cc060185a40b94143050e201b0a7f74269953d3a113ab66e752030043721d04 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-workhorse@sha256:7bdb3fb29e35ba6c357074920b2d8ed16fa8b11799ddaac0500ef97bd320234f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-workhorse@sha256:e8c615fc44244c80ab687991cf657bfab9f93a3f432d2498a990f5266eea08dd |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-workhorse@sha256:800bcc02cf6da9426ed7d2bb73b1bb6821f06b1ad1a12a483ebb7bb3baf2982c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-workhorse@sha256:9cac744646ccf21e2c5fe811092febf536974dd417003836d10aa59e3e8da77d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-workhorse@sha256:cacb93793b4e7be881ba99ff4e21ec71f2e05e6450e414b86a15f872179c2d48 |