Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 19.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.1-debian-dev, 19.1-debian13-dev, 19.1-dev, 19.1.8-debian-dev, 19.1.8-debian13-dev, 19.1.8-dev

Index digest:

sha256:a7adbc28f7670329ea9f04b13a3d8be06bd626df1b18bf307a50ef53c7219e92

Manifest digest:

sha256:fcf5425d868394568bf41a6318406c99854e92b004dc913193b36fd87428be14

Size

668.45 MB

Last pushed

50 minutes ago

Vulnerabilities

0
2
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:818853ecc38f0c5f10f13b45ace3571e894095dee50c2da7ec9cea1ca2a29def
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:a0176ab9a76580ea2dd821416b5999d03ae47bcb47c43cad97f181ef9233dda4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:2f030f90586e0564f29b2acf9272a1b2f257e4e35012b9a2a2c9a4caf9486efc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:47c21f0e1166afd3f0699322d4fd0b6f20239fb31a83ca0f5a1f30c27b57ff89
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:5e0a404c060254b1ae275bf0df7fa2b81cb5e00d5ab56294660f8f4d021d5c61
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:f90d4a28de8b4d608f7fd50b5e084591ae865a641cd3466587289f602ebe94d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:38b8e7079cb1c3c73f890d22f2e0decbc37786a58d26abe0fc17c8c72030a848
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:9f2bdf6eb777a6d40e8a17dedbf8fb0c568ffcfc2f93eb673961ce4446a2f028
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:ff0c2ac630cebd26cb4b9a65d57ec1b482bc264f894a87ef1d630de43fd90c99
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:41342642d92a0c8874613cc2848e757f9345b3b9c026ed81b3e99f225eea22e4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:c1771fe7787576556ac27dc6d2683456a628e2f4a3b8ab02ee65db84ba1b3a1f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:edd6241e76774018955f02b8af7189527ba0a9632bd9ab11ecf9c4167022b380
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:1b9e810d889a717133619e26ebf01a50290fc4b68dffd0b4326497efebc65ca4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:27b547ba3ba6ec83994ee62bf54db7affca3cc07cdb596715a394b7c15e8b77e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:7e37343faac22e342aeda7613bd68e8b8f4fc70d3528a661d9067fe545d7aab5