Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 18.11.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.11-debian-fips-dev, 18.11.11-debian13-fips-dev, 18.11.11-fips-dev

Index digest:

sha256:045c68f5bffa8926a65636e107bf7bfaf489aa820c0d80127d1a4f62859d53b9

Manifest digest:

sha256:54ccba576e2a93eb9d4de8c08b22961d2f325e38cc5b869179441a9028eeb7b2

Size

666.45 MB

Last pushed

7 hours ago

Vulnerabilities

0
2
9
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:824189e6e5217d6e682f89d7f1a3ca87e2ebe78efa263887069d95d33c388784
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:c8e091e95c65a75272662dd2b3277a5799be4503c58661002c6daf79ec60e163
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-webservice@sha256:f35e4e026c8e79fced7ff4d8451c674fa5bacf5829e2ddd0d6b2e314606b5890
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:1c6e993cfc4f9f998b800a5f315257824b756078c3801b76da23a4f59221dda2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-webservice@sha256:79c518b848a9575663ec8bab76712b2377faf3492df1373dc775965a2b3109ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:25a5b45f85a6a399d1a37fad88771da68ff702c3fa3940d3ac2db658ff533def
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:848b9c84be6af0e404c3ee06e5f42e5cd08644e93e005a4e45437914970a2380
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:852878439421b6430325bbdafb57ec880a1baa95544bf182dd8dda90cef2a743
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:f23af043c000667f0ba1f578f24f116afe88de0fa1dc162f6f9a70458b0ee163
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:45158e9e178993a4223823fcf3b0de0549b38a5c2ccf02d0dfa348ca72b986b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:a3bb804156ca207df1a642917c7d433273a92db35461a81b853f227cd2b82149
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:517ee840da5d9b8eb0d2fc93b60c68557b1b01eebd256a0c8b313a75efee18d1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:a528a26438003cc3c74a4ef71b4e044dd41a6450998afab4ba7c85266ae6a5f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:c4f0196261af26270936506dd7a4f29e7e696a8a45053a035bc08bbed4d94f67
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:b46d0ece538b2a7cb2243822b9b99373b77cdea300a2f8a9118596134699148d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:c8177e57e37e2e698ec0adc68b5dd298eb64ddacf24ab2710389fe2450911f29
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:820808d631ad4b39b972791eded368c0fd3923ea944a336d16e4f76330eb8664