Sign inSign up
GitLab Pages

dhi.io/gitlab-pages

GitLab Pages 19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips, 19-debian13-fips, 19-fips, 19.4-debian-fips, 19.4-debian13-fips, 19.4-fips, 19.4.1-debian-fips, 19.4.1-debian13-fips, 19.4.1-fips

Index digest:

sha256:8ff35e1a5749f294ef97d2d65106ea9ad2138b53efeea330b4ed693531a6142f

Manifest digest:

sha256:3897dff45fc62747d8dddb85164e9be65e476eaf0766f925463edbed50f81aa1

Size

20.15 MB

Last pushed

49 minutes ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-pages:19-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-pages:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-pages@sha256:495f0a467efba5e0cd35ca3bf1b11b4c843028e8629a4d53d4989a90e97337c1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-pages@sha256:aa056f2a6b5fa3c3f091159bf072d29718a3f3f7d003cea6f75cdf5196eb877f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-pages@sha256:2691aa555479138d1f2927f3a8e1f9806d18da178a948e5e4a85fbd5c6f235ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-pages@sha256:2c12c0b9ebe9fa4cfa196df7034193c683177cf0e6741724d2228911f0a7b373
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-pages@sha256:1936e31e18d1e40b34297ce327f501eabc4661546c9443bb264132f4c2da3ea4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-pages@sha256:04a6279e05cbcb7cb167a091eca83245b8e1d92e7a105303ecc66e12a8dba33f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-pages@sha256:1e4e986284f9c803fe93a147feb06b3ad1cd1e12254f38ff990549e2e7577ae4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-pages@sha256:f2226190c77815d62b10a56dd3e518cb9301e7374f17dc71c7a35a3282bf52c8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-pages@sha256:e538fa71b498ccf7d29172dedd050083a30724c0ad880892674d810fda05ff9c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-pages@sha256:f69fe7c37ef7b9743ff7e2fed2ba4703724ac1a39d1f50b9aa8bda0ce460573a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-pages@sha256:fdbb75e55566c337aaa352a4df06ee5f211eb7db5accc46cea1ab17d041fdf10
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-pages@sha256:355eb2de81d2eea2fa0b8414474446313cd2f0cdf762083ad074e6fb65282f13
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-pages@sha256:575ecd162f282c765dfd806ea5517aedec45c0c6dd1a2f46dc59cb36db751002
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-pages@sha256:cd8ef663ff261650b73a2c34cdccfbe7ecc0b6c5b248c5754025cac11d5b5236
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-pages@sha256:dedb5ba8f68e2da6a5fb7a14c82c19ec67623d60b199690997d2b2a38aa52375
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-pages@sha256:cf221fb08f39b2f98e253b99422057ad79e47bbdfe59a79b5baaa6d4fde0e4eb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-pages@sha256:d872a67c4bd707024c45acb9d4c72dcf5682b1a807b8ea370239151574dc0001