Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 18.11.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.11-debian-fips-dev, 18.11.11-debian13-fips-dev, 18.11.11-fips-dev

Index digest:

sha256:5e90f4e57da523737f52729f70fff16e095524249abda8b0fd2ad81f60f24821

Manifest digest:

sha256:377e1325b515d76ac73e6cd3090f283b9e20fddf2548fa676cece66b3e0d8e51

Size

666.36 MB

Last pushed

7 hours ago

Vulnerabilities

0
3
9
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:62566ed1376dbd42ebc51b22b75ec0d741ffeca062e21eb660a5fb38a292f26f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:f3975254c91c45d06fe0c03337497d66a30d54672612fa1a1a7b4c22258cacd9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-webservice@sha256:d9ef0bad0eee42d5308d6f7d9eca232a9afea7dc2b3ed324751f34055cd8e14e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:15e5379ff95e9af8d449fb69825506a5473a8ea6debeec0ba10e6bb3788c0c14
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-webservice@sha256:803e3c845319e82125eab567b638fa5b268d78864236918ff9aead94a12dce91
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:0d7ff38eb3bb2d2def1da767ce020d444616c047fa95ae36aa78dc00f5e0ed84
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:0ce4291cbc64831b2797a27de41ab2c4eb347817609680670db7c913b1a2a493
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:3e3d6a67fd3bdb8926b2bf378da1b4cc0e3b1e72cb79cd7816fddda5ec0ae671
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:af2721d4fab8913ff5945d610d545af27058bd2be280814da1b6262a4798e637
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:9412cd312fa1eb22dc508e857a03605737331c68316a6628f62f806844a89c40
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:8a77ba5c6091fe6584e14f006b36429f1d766f6d411f6e56ca16430dad12f3db
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:e662a0bbaee4a22e0ff26e3dc4a194205e84981485d4092df4f4770d1960f992
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:7ffbb354cf828500f023a8be480885c9278635fc61004d2b09c95b026d734ed7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:be07428aea60bc75d51427e9f6a722f55b087a9f093d3245af29708f5f8d2ed5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:5e38288f66e78f6f200429f0d30ee1ee37f138eb6566f6425da83eb75b522bb3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:96c8f80b6fa2e65ebc3b23680da5e5ecb09546ccd150d39901c9f92fcf24288f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:1a37696fa09d7cb32688e788fc645fb4283c205b36e5a3c96f7f1e974d2659ce