Sign inSign up
GitLab Container Registry

dhi.io/gitlab-container-registry

GitLab Container Registry 4.x

CIS
linux/amd64
alpine 3.24
Tags:

4-alpine, 4-alpine3.24, 4.42-alpine, 4.42-alpine3.24, 4.42.0-alpine, 4.42.0-alpine3.24

Index digest:

sha256:861d9c02f3731ffa5462a091b92f41d850695322d80fb42e56028904287b3d3e

Manifest digest:

sha256:0a0eb6187fd34fabc595bc4dadb7e16932a6ee36166b1f20131bfe7f820af68d

Size

18.24 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-container-registry:4-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-container-registry:4-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-container-registry@sha256:9f5f22d96d2ef6adfa520446a77dee551e98ece44e4ed6fb477ef6e32823addb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-container-registry@sha256:010a593af03115c495d73c8f2dc23bb9934bb4eb2a935913795bfcf62bc7cf3c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-container-registry@sha256:cd54b44cf4292ded5163680e4f723169161a3f20a75feaf2a73d5bd048cca47c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-container-registry@sha256:e5da7d1f2423308f4390de26516a8e38049521ccec306712ab660b38f14ba7be
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-container-registry@sha256:ef8793e21ad6add9fcfa92684b9bdbca7ee8b7710d3f61d6689266598f96585d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-container-registry@sha256:31f40a49d13102729d7150f0f5ed2501533b88399675af755af3be8465ccba64
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-container-registry@sha256:f7a8a72f99b9c7640102af388467a08f899b10c9ca060a8b57990da9bca50d72
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-container-registry@sha256:b64c81bba5756f9bbb0b363984f3561e3776e3628f3711067d1aa5a6044bfefe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-container-registry@sha256:ba656e90f178750bfd77b740f4c6f5c11ed2cc977c6bcf11cac9826dfbb18a92
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-container-registry@sha256:04f06b57a5fe31434ccd00d221a4f47e6c44600260eb6509f38587dd0e033f6b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-container-registry@sha256:3b77c105e1d23ed9770f62285ff46674e831442acdcfc008ddd462e72f395e9c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-container-registry@sha256:64edc2121cfad9cafa2a63212e6c271101fadc3f5a10c881c128169dad3868f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-container-registry@sha256:d4c6a27134db8dd943f5a89c0c1c8a1bfa1fa5a54b6a83b6a34415d5748ad4ce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-container-registry@sha256:7621abc374d8f7d8eb9c075ffdf076a899ac5c1f8a370d484ebb47b99dcd4055
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-container-registry@sha256:1b99a80a1f6d6e3eadf36f7a30e70f4e69df1032b1051e22ecc718c1fcdcc8bd