Sign inSign up
GitLab Webservice

dhi.io/gitlab-webservice

GitLab Webservice 19.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.1-debian-dev, 19.1-debian13-dev, 19.1-dev, 19.1.8-debian-dev, 19.1.8-debian13-dev, 19.1.8-dev

Index digest:

sha256:6ef2626f16b9a00e027e3f506f1e7f77c7167a12b6884bf880ac07ef7d438256

Manifest digest:

sha256:23626a57c34896c9bafe595a897b248e934fa726473e94db77862a5a4b0d440c

Size

668.46 MB

Last pushed

9 hours ago

Vulnerabilities

0
2
7
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-webservice:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-webservice:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-webservice@sha256:88a5a07abb331cf20e832b5711739cd5bf43f92715d8649b80c909627057beb1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-webservice@sha256:e4a18777d48b830da022ff14e7634c8281212f2791ea4b776274d5fb108b6f7d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-webservice@sha256:e597fa66950aaa6f6819d5eb65d746316e107fdb765d8361ae45d2701b0e04b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-webservice@sha256:4b1cb21c3b56ec1c606dd316cc71de97abc7f6c47134d6042bc6f73a596cc0dc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-webservice@sha256:d4ccd3b89f68213fc1f6b33cab79acb518bc8f145df5c5dfdf77e5f7e2e0488a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-webservice@sha256:84513db7909de086caa4522a962be730d531ed7b77309bd3cbccaf843e8ad504
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-webservice@sha256:1ec06ffdcc83b2dcdccf8de2ca6b08a4b540b5c992e4541ecc7d9099c58aa4f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-webservice@sha256:22a78016a49229ff25dcc3ec080b1bdab843eed442800a822148c94b2e8aea55
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-webservice@sha256:513ba5e6050cbd29618d2ae8a279d79c239aa6055886b440627e400420fd6a8c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-webservice@sha256:6beeac94a30f857a8b4cb06a22bf65849e50064a2e4b2928a9f4c1abb225ad14
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-webservice@sha256:e1e37445e6c1f005ded6c1b3cc9f3b958779dac2234a619f2c16e68f4b2ae691
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-webservice@sha256:efacea0eabb6af8c73e514d844424988635a071a4caeb0386b8807e78a2648fe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-webservice@sha256:1321e1bf469dd947dcf89019e056f46c123a18d92feb88d0caa72434d29095ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-webservice@sha256:b160a32d503dd09e4bf7ff4101dae7962f0493293717c6fc6fb8b9def40ff420
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-webservice@sha256:f66c4efa9ee28e168e315092c3a2be6a47a1e652764b9649ac373cb97aa6f8b8