Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 18.11.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.11-debian-dev, 18.11-debian13-dev, 18.11-dev, 18.11.11-debian-dev, 18.11.11-debian13-dev, 18.11.11-dev

Index digest:

sha256:4c5c0d052765f2848243cfbcfe3d856af1dffad172ba1cbbc57ba594676480c4

Manifest digest:

sha256:17e66c232833734339fd433cea1c1087d342f6564f7793f331a5e2fb141f8568

Size

665.70 MB

Last pushed

14 hours ago

Vulnerabilities

0
2
9
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:b894ab5dfbe97068b38f0e426d2b30aef8ea4cd9f5cea55edd1f094e8fe77205
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:2b525960138328add8ae49097ef7913f1b683ec5cf74d462643686ae7e779249
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:a17e016b27571143a8a42099fc0e060382867d19a3e29ab891ee69659b73b692
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:bc48fe6a0677ab6828e5163eec370ce89aa24e522d8b5c6397657617ab14fc5c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:e6e6b2d912afa332ba051e45298292ad3dfd37d917b79799a04f001ce0ff03f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:fba0590b0437020ae40eef9e13f619dce3ab3fcabc57649a38dc9e274045c804
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:bd9e90f405af36924ed72312c8a36f6a57f185adb4be997ac40c86ee9a8b8343
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:318d1f48b15cffd00245449327cc60a0a4c00777add77789a5ddb2558565c83c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:7dd0be753e68a9c5d42f5054008edce3d970c89be94c9710eaf328a0e4aca602
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:71ae7f17fe28a3f72b8cbfbdc266f8346de970b1b12139e359d55ae2b7bb574c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:269162bb869ee2b4ddcb8d1aa909ed639c2898d68465fbf2578e2f171b1f38aa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:d0b812a53a6832816dd9645088a421f01b9aa9a11771961a4338098f6da3887d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:4589a9da0f97a593747e6c1e906388a4b97bac50ed2162f0f3cac16844d21ffe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:faceb2d0b6e2ee4a0eca204a99145aaa35f2ba45e9e29c54ded422b81f738193
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:e97be9fdca27ae5169c101e87b4a8a10389705f14345046187010a8076aadac4