Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 18.11.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.11, 18.11-debian, 18.11-debian13, 18.11.11, 18.11.11-debian, 18.11.11-debian13

Index digest:

sha256:491f6b7e272296394f244dad29a7f50839f34fbba0cb10dde7f559dce5f78e56

Manifest digest:

sha256:fe9ca720903b98dfb8cc025ad4af58a101e8ee8b2af3a84578af9d3ed3599a1b

Size

582.94 MB

Last pushed

6 hours ago

Vulnerabilities

0
2
9
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:1e55558f86ef680178740236272e44f22cf4d1ee02ecd596cf35c5faa3e6068e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:ce65990409870004445535e7e1c78c814c5bb57814ca8787e438269868bcbff9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:d30fd1bbafd58d1dcc550b0a9158b98f472392d3d0a3a1640019b4e82e4f088b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:bc933f04b09c8403ef1fad5031c86b22cfee95d0d4bdc5c83e762c17e15821a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:ec16d41991b7ba9c7562b14da55142b480aed5952c2828b5ad5b17e2599c1f67
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:d6333abdc423e01b66c20947fd5a1f597399d2b4d1cf4fd027d959e9f1c85e2a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:95efb115bb08958b242023184b2935edfaff5f540d00b1d7e5ec5704a954a3b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:4743ceb41c417c15313a7b6b56cdb2f89b84f1e33add17aa840a04ff3e08f1c6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:5176abdc1f92a27528f4842eb8f61a17004e755e52b82e520b55a3563739b119
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:0d5743b2db9a6c53728838912d2f5ebecaae0b33fbf433b813e0ba5b87173a57
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:4e31d441c60f83606f039149a9bedff96533d39514dbd30099edb8b32f5f0cc4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:809f0480e889b3c3e317e188101df1bee6126542475db035a21d833975b51d67
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:cc31aff2bc5875703c255ea9d4a46e539b7d14a9b27df5396ee8d8f6791ecf23
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:783f44c06bd8303e21f4590d61ab53fa28d669b5bcc75cfe61d26108386d795e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:b9fc1510159ee796d15fec5e20f526dfe4268efbe8de4c9e41cc1537238ecca8