Sign inSign up
GitLab Workhorse

dhi.io/gitlab-workhorse

GitLab Workhorse 19.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips-dev, 19-debian13-fips-dev, 19-fips-dev, 19.1-debian-fips-dev, 19.1-debian13-fips-dev, 19.1-fips-dev, 19.1.8-debian-fips-dev, 19.1.8-debian13-fips-dev, 19.1.8-fips-dev

Index digest:

sha256:2231a99f127b78a7437087f3f8243c36c9d4acfdfc5b19be92b9d6104f0ca9ee

Manifest digest:

sha256:f19e95df4a63897e4816a81e13f820e8c0340ddc5d2153dd9aeb21a8d7e0a005

Size

324.83 MB

Last pushed

7 days ago

Vulnerabilities

0
3
3
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-workhorse:19-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-workhorse:19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-workhorse@sha256:910746cdb3dbbb5bb27650c3e6a1a1efe1187a6197429c77de085d201c1ab592
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-workhorse@sha256:bdeaff93d917a79f9c2c65d9a07eeeb30b41e566a837b89cdbfbd85ba9087331
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-workhorse@sha256:f27909a572189488e21c221a7d5c33199d35c3aa8d94a20f670b6352282d2bc7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-workhorse@sha256:f9995f418b3da3505355f37d5b72404537e98b121be96817435fb50f11aa4c6a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-workhorse@sha256:3b4c3b9731c933f98f1cc8ef7a617aec033037f700355060509a81bdf44499a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-workhorse@sha256:202c50a1ae13d5f79091149499b90d8d120f1796117356d6beebbd6e348f7917
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-workhorse@sha256:13c1ec065ab97aabfa3cb55f5255cc2c600ce12a597039fa60cb0c6bdf89861a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-workhorse@sha256:eacf569f33ebeee088f3c918a8fd209b593cf7c3561b4af997d412ef0036fd4f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-workhorse@sha256:e79ef42aa4934cd3777e619281441faf8304f5b8fb06445b7e74ab2386369717
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-workhorse@sha256:b1d305a5027f05d549bb801dfc37f43f3168aba5f37b4f3ab102faa02f4b5e78
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-workhorse@sha256:b3c9d2907ef6662377fc332cb6bf3053cc9a9e8ff264f1c739239e0e5349bf75
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-workhorse@sha256:3133477c4d86636e19d3bb9f2d8ded864d8fb1b44b6dcfa0f958f3ef5a652c38
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-workhorse@sha256:fef85529c7ac049f88994500546af037a72789b6f5b25c2eb400b55681c6ab98
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-workhorse@sha256:60172e49f007c0d4ef4f09bb00d65310e91555e693c85857901c280fe6f3b05c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-workhorse@sha256:4e0d9a6e3d29c2c7615be8dd8d790ca346ffb745668cfaeba3fd58ed7bbc577f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-workhorse@sha256:dad3fda74e32f5635953cbbcf47c60bf61906c1cb8701110c461ddd0bdb84cd8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-workhorse@sha256:f804f4f8bb37c5a696d97615b8ea4e998eb38d726f81fb6757920f0a1badc4c1