dhi.io/gitlab-pages
19-debian-fips-dev, 19-debian13-fips-dev, 19-fips-dev, 19.4-debian-fips-dev, 19.4-debian13-fips-dev, 19.4-fips-dev, 19.4.0-debian-fips-dev, 19.4.0-debian13-fips-dev, 19.4.0-fips-dev
sha256:adcdb29398d6f3f87ab7ba270fee42a638aef6a0e9d03999b3f175806176a1ec
Manifest digest:sha256:b792fd4b1007ca9818751aa8853164dc1e763f1294677220b32375bfcabb69be
Size
36.06 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-pages:19-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-pages:19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-pages@sha256:bf2db16d5a43a3efe01155c9a72d4000b3285edecbbe7b721c68a4d96059a3fc |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-pages@sha256:80f612bad1c8804d63601e153369d8289d4dbfe1454a32d527137a6f889d3d70 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-pages@sha256:6d2ff11c16e0c3bd9e5f1b098eec27c3a5fd80414dd2407e741b05309ef5fbb2 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-pages@sha256:8fd8ec80c40f3f1dda92bb11cc981bba9b301bbe1b66a6ebf37398c73af2d746 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-pages@sha256:f4cdc2af868704567810325be224205f3de720eb006bf632d32f17446fa916b0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-pages@sha256:471832d81f110cb07065864c6fb65126d633989a4b6c604e1016b5864a0d9c81 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-pages@sha256:2cc12bb9444e0938ea97e266333629867c2fa0b13993d8bb2665537a789ecd71 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-pages@sha256:ee52068d5b719ed4aa9efd3dfdc9f1c00f8033c464fb64a9f945cbd268c8062f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-pages@sha256:c5a83095dd5a0029bed972fe39431d5129e20f8da93c96bf295c4076cec221a9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-pages@sha256:388d8a78d12bd2449a5c60041486d184bbf0cf62b24f3bacd3562a512016c67b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-pages@sha256:eb43a87c695e778c9f9bbdc820c97e828f0701a956939c4b51964e0c4ec28db2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-pages@sha256:9ebd85c2972c4167b1185dd83ccf330e3064fd6581f1554730f39ad1877c97ce |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-pages@sha256:b96be81b7a8483cdcc161fe717f48a5a12500d859c096ea002580c569874fd00 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-pages@sha256:2bf49963e69aaeef3ae14d0504c74c9ba21a995efd3b574193bf068957ade2cf |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-pages@sha256:0664073e2b3d8d5a399adc1ea06392c660982aff56ff680f1e15e50aabd101a6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-pages@sha256:8b41bc91588689b87ba60786280f5c1a98b4f920fed145d3f4aee801a84552e2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-pages@sha256:089afe88dedcbafe417771731fae9a0d4659c21cf9c95243967cd1926fcd0f18 |