Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 18.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.11-debian-dev, 18.11-debian13-dev, 18.11-dev, 18.11.11-debian-dev, 18.11.11-debian13-dev, 18.11.11-dev

Index digest:

sha256:a9cdc4203e7e0510e2935a41162e06918010fbb8c01d1679a325fa5b1e4b90dc

Manifest digest:

sha256:b89a185084aac268a9c223d5a8a1b717ccb8bcfc0c2d3196d88fe3cab9c69632

Size

665.59 MB

Last pushed

17 hours ago

Vulnerabilities

0
5
10
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:8521925896faecee41e67651feaf57aa00ed06b5251216522c7b6e5cff81fc53
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:12554116da480b698f799ee3ff8b9ba1979a0317ef21734ade17e083a3690f18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:0be49a4637093685a56f96280abafa5f31d01ab76045aed3615c5e7dd2ab08c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:933cb72c307065e4e9f4de50e86a4abc832c26f54a072c4e230811502f741dc5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:963b4a648c9d575f80641426f5de27af327cde5057da50dcbb5f9c085df46a07
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:0140c86e9d0c8074be2cccb5fb71424bfa2598186e23df2284759cae1a1ba9e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:aae8ddc7c143dba818a3d022b7b143f6ef171ea9dbbd2c36ccc0269e4768c6d6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:657188b55640f6626e493e696cf923c951fd3c8fd40306b1bafc1b21d87ef9df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:a908979d88672e8beb70885ad0521b0926ca17bfd27372040670500c2127b1c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:8e052136a5d097f3d45d3d6e355f8358748aa818b0fff8e10d48417affd4f053
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:6f2ca87615475e931e00e8d6a48830385d6986ac344e6b28f21e40eb9cc08742
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:d2fa5617be3cf3d0c9b41ff2655238e754e576947ad247b3d60f21325825b4fe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:4c049641a613c841979fcd08d44d5eaa931e6f9c89298c1c8f32205f62f5aa81
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:8e6af8aba3988ac1ed935cef737f54ea4d21a6a1ddd4fbbe0016d75102875e6b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:bffd9e5702230afd72752c6146621b737e623b60bfda28eb229cc966ddf26f91