dhi.io/gitlab-workhorse
19, 19-debian, 19-debian13, 19.1, 19.1-debian, 19.1-debian13, 19.1.8, 19.1.8-debian, 19.1.8-debian13
sha256:9a004783fb8bdd4ee4a2b0e7f7e3219fac09758219e9223ca9340a60b1951aaa
Manifest digest:sha256:1f0ae10de28b8a72ceb42e4771766b282b8f8a55881b2e65badae16940760631
Size
314.25 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-workhorse:192. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-workhorse:19 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-workhorse@sha256:b37db915fd9009d550e7dd45f8724f456a5836e528a3fd70f1c54134bd118979 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-workhorse@sha256:742f681518a1eabc3496a4dbb165f8f1bd9007a0a3ee59ab227e836aded1c86d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-workhorse@sha256:a2148249505dc1b99dc733f4aab76c74863aa65a1f2bf1c023d24236dcade00a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-workhorse@sha256:0153427484d61b9641e52672cdcc4e017696c1949bd4cddceef5b249542cd14e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-workhorse@sha256:291a8c7b7b252b57a87a245593a4050a5abbb7de05682cdb48e6b9bf8722be6e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-workhorse@sha256:de6f01923e24b713ffa1fc23e214345483822d1c0c9c2c86916e5d85cdb39fca |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-workhorse@sha256:5db306bcee1e7aabd0ddc3c5687db26d20253380675046e6c3e4a49192057360 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-workhorse@sha256:25abacc9527f5f72ca110d55ef4669f7f17ef5f12db2ca5aa8a6eaf12fcf51db |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-workhorse@sha256:785fe3f706dbc69f29777c983ecde3e1d6a7b73e47257aa90f8831f9a56aac01 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-workhorse@sha256:3a64de54377bb969a3db8de62ffd04fdf7d40022b22fecb878dfb548d785e167 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-workhorse@sha256:2f3a006935ab47202fb84bf78aae25ba9a7fcace632eda8f4595fd02d1ebdf5e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-workhorse@sha256:dd8a7c3fb76a7a201e141e8df664fe3c06407f0d7f6e1765e10097968ff4b41f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-workhorse@sha256:a06b76bb8974ea22b9e588b56056e47e6cf789d886eca3c8379d0acdb450c1af |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-workhorse@sha256:2e8666597521a13223d0d07e07c272895ef17879b79f085c47850e7426c7be42 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-workhorse@sha256:98e8065318af7a403ea3e15166134322eeed043f6c59cbd81f3d14c8e0b9a86c |