Sign inSign up
GitLab Workhorse

dhi.io/gitlab-workhorse

GitLab Workhorse 19.1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips, 19-debian13-fips, 19-fips, 19.1-debian-fips, 19.1-debian13-fips, 19.1-fips, 19.1.8-debian-fips, 19.1.8-debian13-fips, 19.1.8-fips

Index digest:

sha256:59efe39a99bf65646e007244db5fe5849e6d779103df4ee021a9824547943147

Manifest digest:

sha256:38e6f6ead84e0dfd96e6455f1d7a5a344f786d22ce957652ff731225bdd57d82

Size

316.47 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-workhorse:19-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-workhorse:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-workhorse@sha256:64c999931c880c28c172d526dc858a901e3d9299ef79a84323b4172fe2a13aba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-workhorse@sha256:b12f752e64a6390948e59688d7da9916be04e300a7f53bbd3f2127bd37b49779
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-workhorse@sha256:66d3b96e4517ef5b62508afec71589bb74978dfe9e8eaadc6a636c0e428726c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-workhorse@sha256:264df557a74d413202ea0f7fb5841fc185a24297532fc978dcec0198291fb19a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-workhorse@sha256:5f36a3d0e0386bbfe51c4220fccc3437901dbcdcabdad3f00793b87317e0b07c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-workhorse@sha256:211fbd6b70baaecf3f0d3f50f7a2d7ea7e1b80963bfc1e4ac34a3fa3d6322261
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-workhorse@sha256:ebd941528b5721971567568a2beeb9e02d250a48505a979232dd3e536b4b2b2e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-workhorse@sha256:4f07fff5c8980870ad522196715a950597f21763830fef0f32e4a7ab0d03b16f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-workhorse@sha256:9c051b85b7a8ace55280c3b17f364a9a577564ef5b24fe1aef8fe22cf20119da
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-workhorse@sha256:78f8f671ff83fe2b99f6e8ca3e737c6b24d909708ce4a76826b68fff6003afd4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-workhorse@sha256:dea3d4fdccbc416a967719afe68bb057bfb087c6401314b6bb33c23bef54b965
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-workhorse@sha256:a1e6ad015233da8504f2b8d37af0815a5a8ffa6f7bccd12ce1cf0a008fed4939
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-workhorse@sha256:50b669c280ffb674567f1f22e7461ec5ed770189f61947f5ac3a33fa3ba2a1aa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-workhorse@sha256:d50c88024e1ce1c2941395a536add2e6bba4cb0671574a9c94859a20c0a67c4f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-workhorse@sha256:17d1e19e2e12347017df9f072a72867e2211929a27033e6cdfd2507c153b3d34
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-workhorse@sha256:f55e883470dab3e6ac1443e93a3dbe73bffca0f142d86960e5b96b52bae50558
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-workhorse@sha256:33376662851d8cc3101819140353d26ecd9ba263ea1943f33c7de1acb3f709ab