dhi.io/gitlab-workhorse
19-debian-fips, 19-debian13-fips, 19-fips, 19.1-debian-fips, 19.1-debian13-fips, 19.1-fips, 19.1.8-debian-fips, 19.1.8-debian13-fips, 19.1.8-fips
sha256:59efe39a99bf65646e007244db5fe5849e6d779103df4ee021a9824547943147
Manifest digest:sha256:38e6f6ead84e0dfd96e6455f1d7a5a344f786d22ce957652ff731225bdd57d82
Size
316.47 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-workhorse:19-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-workhorse:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-workhorse@sha256:64c999931c880c28c172d526dc858a901e3d9299ef79a84323b4172fe2a13aba |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-workhorse@sha256:b12f752e64a6390948e59688d7da9916be04e300a7f53bbd3f2127bd37b49779 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-workhorse@sha256:66d3b96e4517ef5b62508afec71589bb74978dfe9e8eaadc6a636c0e428726c5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-workhorse@sha256:264df557a74d413202ea0f7fb5841fc185a24297532fc978dcec0198291fb19a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-workhorse@sha256:5f36a3d0e0386bbfe51c4220fccc3437901dbcdcabdad3f00793b87317e0b07c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-workhorse@sha256:211fbd6b70baaecf3f0d3f50f7a2d7ea7e1b80963bfc1e4ac34a3fa3d6322261 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-workhorse@sha256:ebd941528b5721971567568a2beeb9e02d250a48505a979232dd3e536b4b2b2e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-workhorse@sha256:4f07fff5c8980870ad522196715a950597f21763830fef0f32e4a7ab0d03b16f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-workhorse@sha256:9c051b85b7a8ace55280c3b17f364a9a577564ef5b24fe1aef8fe22cf20119da |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-workhorse@sha256:78f8f671ff83fe2b99f6e8ca3e737c6b24d909708ce4a76826b68fff6003afd4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-workhorse@sha256:dea3d4fdccbc416a967719afe68bb057bfb087c6401314b6bb33c23bef54b965 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-workhorse@sha256:a1e6ad015233da8504f2b8d37af0815a5a8ffa6f7bccd12ce1cf0a008fed4939 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-workhorse@sha256:50b669c280ffb674567f1f22e7461ec5ed770189f61947f5ac3a33fa3ba2a1aa |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-workhorse@sha256:d50c88024e1ce1c2941395a536add2e6bba4cb0671574a9c94859a20c0a67c4f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-workhorse@sha256:17d1e19e2e12347017df9f072a72867e2211929a27033e6cdfd2507c153b3d34 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-workhorse@sha256:f55e883470dab3e6ac1443e93a3dbe73bffca0f142d86960e5b96b52bae50558 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-workhorse@sha256:33376662851d8cc3101819140353d26ecd9ba263ea1943f33c7de1acb3f709ab |