Sign inSign up
GitLab Container Registry

dhi.io/gitlab-container-registry

GitLab Container Registry 4.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.41, 4.41-debian, 4.41-debian13, 4.41.0, 4.41.0-debian, 4.41.0-debian13

Index digest:

sha256:f25b5015f0b6748d47b6c346ba8ba2aa254c9f56625431199ef2fa46c1aace9c

Manifest digest:

sha256:010aba370c001f31df282ffaed1616845b855d120462551944e9d763aca1c5f3

Size

18.03 MB

Last pushed

30 days ago

Vulnerabilities

0
4
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-container-registry:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-container-registry:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-container-registry@sha256:c16c790c7ec7588c500188d8fd9e3bd7814065630bd35846636ab418fec9fa17
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-container-registry@sha256:0e0ae64a2f8b7141e5057bda4e20c6c73c5a74aa50f67d69f4252b5675f332a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-container-registry@sha256:3213968b639530a5c1a625f2799e8aad51334d78ffd9de1fac3034dc0a7c6b36
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-container-registry@sha256:f683f0b8fc3ea0d78264fe2c9f96f0b36b42c84b6734794f6491f770737f7c06
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-container-registry@sha256:739163c78b2825323e3792aadf179747fd013e933feaf243ddd76474bcf07b12
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-container-registry@sha256:e45a8fed791913c63e9ec4d25db81cf81360c6a4e1e83d7a297de0a2c524631a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-container-registry@sha256:3c933e1e56fab3e9b45fe331de99d35928683705f6137471d8feffcc454c0d4d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-container-registry@sha256:73c82855a0a59fa3b8b379082158effb5f2ec9627ac0cf0bb13781fd9d0773ea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-container-registry@sha256:ef6ea8ceb6778126ec3a5cc1bb5ba6359254569c91907cb4f5f7cbc607de42f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-container-registry@sha256:12abf2f4372647eeba26704dabc9da9b01b33fc3cd002e7a3d9a8a1e9f6c832b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-container-registry@sha256:0c8aca583b45d4f337eaacd58e5908b4dc421c259366397a5441f84b0bed1d5f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-container-registry@sha256:69c0a0a4ec3098eb66b53276ad6c18242a5a2e407253b0a35833f855ca6c3a68
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-container-registry@sha256:ae401678879cb9c41a53419ea59cc244aa2eab3cab61af56d1e93496cf29802e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-container-registry@sha256:f1c4a4d791a9afe90de0ca5b5591c9f5c87ee647115e8acb28e587f5b4fd23d2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-container-registry@sha256:c9734fd5513a289bac7673e056b121fcec3952b48ff45158c67143c56992419f