Sign inSign up
GitLab Workhorse

dhi.io/gitlab-workhorse

GitLab Workhorse 19.1.x

CIS
linux/amd64
alpine 3.24
Tags:

19-alpine, 19-alpine3.24, 19.1-alpine, 19.1-alpine3.24, 19.1.8-alpine, 19.1.8-alpine3.24

Index digest:

sha256:93b00183ceb761bbc70d973eec7e417fa7a1ca0e8593f58df5db8a9bf6506970

Manifest digest:

sha256:1441edb23409ac2b1e80874159471a60ad01c0bd457193d1cd9e6db0082bf840

Size

304.77 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-workhorse:19-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-workhorse:19-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-workhorse@sha256:a1d1d9a8cdf21c366c57798366e13ca1516e2083eacb4ded812ef5de33901e6d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-workhorse@sha256:1a391ec6c2d427b3f00fec2ed3a781c4caeaa0e1517202eab7f3076957845ff5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-workhorse@sha256:3966cc92a1ae1feaf25322539f8e546181b8ff63aa02da17debd31948da62a04
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-workhorse@sha256:62de0b8654da418f6a6b4f644913dfd70ecc81222abe6e829ebbc99deeee7b03
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-workhorse@sha256:fcd893f12a753aec1d7f5af1a724479bfa91a6a3c6b1aa296dffbd980aa51c19
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-workhorse@sha256:e53704da9934b16cefd298b4b2dd815e0c55c62e97cd98f7467fb89520eca70a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-workhorse@sha256:806e914c4ee1639244bd922a66928e91190fc2f75ee2460f70dc2b8f5e8df3eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-workhorse@sha256:d13494457fe93dd80decce028eae219f441843327f40b84f5365acdfcc988a71
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-workhorse@sha256:2c544ae84e1d9ae817520daf4f39c5a113fa89e77a860a7841f6c78658455f49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-workhorse@sha256:dea7c23a72046af01c70e44f4ce7aa7cd47477d85664be204ce1948770193836
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-workhorse@sha256:434902ae43a97bea86cd9435f51b474fc9f5ae6f78b2ce3c48b2b3de97a94d99
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-workhorse@sha256:72c266649c7dbb61fb9dbc5543f6a843a7b315967f7cdf40bbd399720f11479d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-workhorse@sha256:824284a3599f57cb7848f2c9242903ef0a55ee3862c0e39380ed564309d7ef74
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-workhorse@sha256:cb47b22713788b72203047675d9d49e5a8ef6352949b9627fe87420fe7c3a13f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-workhorse@sha256:c368662c30ae77b81187bab4d5c863a2d5e92d748403ff4cfbf4bb2b9a05e095