Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 18.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.11-debian-dev, 18.11-debian13-dev, 18.11-dev, 18.11.11-debian-dev, 18.11.11-debian13-dev, 18.11.11-dev

Index digest:

sha256:3f35a868151dc1e7f7f3e5990815614f78b3c687a13bf51c8694cc4d17bb3aeb

Manifest digest:

sha256:d59b0211e8dab2cd707c1d576d9cdb4cc4d87c41a002d0dd48e6b0be3e478d92

Size

665.64 MB

Last pushed

1 hour ago

Vulnerabilities

0
4
10
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:069b992228b0e1da3cbccc66171dc90766e611cbc6e0235b92a20fe384bcdf45
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:80e0df5a4a4f9d61854c30b89cb7b495ae35b195bb15f6e9d15f3562d43b65b4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:1aa4635244401798e22332ec503809f14bb01b60f80db2ce17daa14d6a86acdf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:b657b3f9e37373747c1dabbbcb4ddb5b36242c0f425158241bc0d15358785f81
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:934b7898b588946b080791398680cbe0779672e3ae589ddbbfdcc972cabf375b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:6ffecce8fe5d5bd243a678b1295321497c9f9e5cc2e9215dfb3c953a323f31b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:322a1251a2a0c602a98a5224d235295094edb40e439e177ff233498d93ce4017
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:113c6b2fe71949ca27a3970931477578c7200fb3e698a7528346353dc69afbf2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:2e5742efed8ae4c3af65c96d69be3f95253df8acc0844c51cc7697189e18dfbc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:a969201623996c5fcb07e64b4eb078c4aa06703a99eb87358bd31eff5cc49156
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:9951e6235312acc4f5c671450335d9ead40865264afb04eb3d198954dfea6cd6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:8e3083910a70795eb1319fb4af1cdff2c33f84bf898461a01379a5bcce895237
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:05b3b449691b4b3af14c92be5298f52ab65a76645cc439b6868ca19042259cd2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:b45ec45efd5aafc314719fdf0baf4e0e9bed6ee58c6c461936dbb289a86ebd1b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:26837653ad3b0b19171291d641ffd5ddc6d558e66aa59d92e14ffad2c113a980