Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 18.11.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.11-debian-fips, 18.11-debian13-fips, 18.11-fips, 18.11.12-debian-fips, 18.11.12-debian13-fips, 18.11.12-fips

Index digest:

sha256:03ef213791efb37f4dccef61035228448006f2e074d7366e16c39c2f09911a99

Manifest digest:

sha256:0a0120c9bc5ebbf7bb867b1d6d48f720e69b0c62afb8986d6522e988e8f91dcd

Size

583.90 MB

Last pushed

12 hours ago

Vulnerabilities

0
4
10
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:f41c5a32a535e901599f2f6ea4800ffc73e10bc8d0301003c6179d04b77b1d54
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:c66a6c08766a71b3e3ac3fcd49553248ba84a0c98d5e99fedfd23ecaa526f179
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-webservice@sha256:81728cebe814927d9d2221e2a84a20b0ce82d62e5d6cf7a73f6eeb06502bde68
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:84c4dd3e4fcfef16ae9e48794bea02ca51bf486801a18eeeab6da0a3e068a262
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-webservice@sha256:ff39328de988b6b8e6d0d3a71dddbc141802a1ff1709ffb30f16eb56532c2208
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:818bf10abf50ad147edcdcef9ff3f3f6a1d40255a19d80cd5f3e0fec1b1a907a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:ec8aa502692c171066f6d8657f0a63342f07b5bf80299853d5b697d3956a4ea5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:250c280fa8b7fd099474e8c078a3867458912b55db45066d2b7172a1926843f2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:837a7e6823f46b652a12fbacf733deee8a7c10b32e2a17398ccb83e7446cac48
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:a1c540dbf9c20c847d31e433ff4ee48b8ebced1811c7c17176ddbf1cb7fec03a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:67a7c0441764f3c194d5c6ceea5ea01b36768490d86e7690fd848d5447f07c7a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:81366bdc6dba7dc11864cb347531e29750d2c97bb9ff983006b919652af08cdf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:9fdebaeda128add2c84bd82adc22511eb76b24798fe4bc21900bd8dee35992f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:58e83b84465cb2ebfc51d1e1c75813fea8ecda98664d1151aeeaa6f392c872aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:b4f68a8826eddbd3a4ba961cc0f3a4bc855c8fda361fe9073f610f9c2c891893
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:33eb216a89eb23d27475091f4aee5a3a42f9c1a703665f2bc7a73359e75255db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:362a8b53debc9a23b9d5debc56ca576dc8a6429bac11b7078abcc88cd5ce9fb8