Sign inSign up
GitLab Container Registry

dhi.io/gitlab-container-registry

GitLab Container Registry 4.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

4-alpine-fips, 4-alpine3.24-fips, 4.42-alpine-fips, 4.42-alpine3.24-fips, 4.42.0-alpine-fips, 4.42.0-alpine3.24-fips

Index digest:

sha256:536bf9ecbd2548c959926ca45a051cbb8f476c7dd9e175a0b603f608443c25eb

Manifest digest:

sha256:10b184d8cf111c02439103e4f329a0444b7dff4f7d2097d5323feaf72c77a4b1

Size

21.66 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-container-registry:4-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-container-registry:4-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-container-registry@sha256:62f4852f07fe61f104464cd0abb869304ce9ad3718a92d42ac4c868e576f4003
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-container-registry@sha256:0e4a87e1a59b11cb1094f2d4d5db7dd4ee3a4f5666177d3dadfc6d99038e254d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-container-registry@sha256:d2888112d7c9bf60023893c151158653be31f52de3b07f1718403c24280c99e2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-container-registry@sha256:997a34d6a936a78c3d31c6809f2e58f990fc3d88292fddb7a215c87d101c3844
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-container-registry@sha256:686fdfb560a74faaa177f2be6eb220c1d0a63fdb60e09e83a0d3f11ec8cb81bd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-container-registry@sha256:2bc605e30f313c33aa6b9cbff145f890a33ea2ae773e07f0b72a5b819f3f3cbc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-container-registry@sha256:50e0d2a142dba801704e473b70b077c0c24447dae1024357916b75ee76bca23c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-container-registry@sha256:ea52825359a445f0b87c2801e3e12ee90b7e0d9ef3e36c975435e2dfcce37835
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-container-registry@sha256:f1dd54938c3fe671116b8e5fa00efcf4782ab44b2f1387f5c32a9e818e90817a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-container-registry@sha256:f659aad37bc5f54b779ac18ef8c9258cbb5ffa9cf41dd7e1f0d0a74f4fd01006
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-container-registry@sha256:852d8268d97806dd2de668a39673eccc971fd6d36c672b2d2220e92c71b5f555
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-container-registry@sha256:0c8fa4df4764bf42fab39483c8e19ef75cd5f4063346a6fc8b946c1473f994c1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-container-registry@sha256:e13f91b9ae399bfda09894d54bdfa9c7e1065dbbbd552a45391c28fba2b7bd0b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-container-registry@sha256:9d446e170263d4a40c2b36fb043f2ec23e555085dd43e7becdc071975160af7d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-container-registry@sha256:2d1abeb6989b77560f1bee378f15c173df8e2fb49041bfc43360420160cbdd76
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-container-registry@sha256:04617c9d2ba4f8a749da4bd757004836f2bae9097a0125c16990c4b53570ff27
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-container-registry@sha256:1d6e17ed4611f96514e4498ca1c0e5d2e9d12480366a22f7bef86689973e196d