Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.57.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips, 14-debian13-fips, 14-fips, 14.57-debian-fips, 14.57-debian13-fips, 14.57-fips, 14.57.4-debian-fips, 14.57.4-debian13-fips, 14.57.4-fips

Index digest:

sha256:14488598a4af9e0df329336b056da67627eac3c39811b64649cb8be5ee52f3f5

Manifest digest:

sha256:e3e9874805645d5f38c092c7e4deb535fd643b43e8157983dfb59d0ce412095a

Size

88.07 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
1
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:687b8cfc32adfbedefb6f779fde65f8c6ee5af39a3f73fda6d053d8d3f116a97
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:827026fcb58226ee1aabb59ab92c4ffef7207c6050648408a12010326d5e6190
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-shell@sha256:52f00bf526337c37c3727f79b5d79324a45930e2bbf254c3f0968f7e217ef6d3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:50a84cc7450f555ea4b5e4a668f22b865d94ef9b1be3fa6d3cfe5eb8b871e3bc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-shell@sha256:dd2b4b8be25ed1ef03facc9d2b6235283b815565a7d84246265c031d417e14da
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:08ab701ff60bdefc457051b1da375ccdc89a0ca4f8c69df7a69abf8230a4c318
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:e52c33082479864c9db113161baf117870f15ccfeb8602a7c92d76c1bcc5950e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:9363d2b7d2a4ad4b019d4944cc2e3f92d1c162093d479a14adbbb36a863a605f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:1c2c9db6382b680f5bd6fa14d8248922527ed583245dddf75e9ad9b42cf3350e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:cc7df9c5fce9cd9e517abde0073debcadd97c0f013822915d83bbc1f47fc38a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:9116c34c0af2f7b850dd6cb0fe7df0a55118a63ca268bb31d3e8edf7acc9563b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:8f650bb0455f6fd99a1807ea2efaf6e25a1e672e305d718344098e1ba14aa422
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:a2e991c578db9c893e242be2ecac087f02774a4a93066a2be7c836ccecf8326d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:67ff9382249e5089842e11af04f22b5a9ddc58f8411e6bcd2218803ef6a8e789
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:74566bc969a386f8822b5d36ce7933367995b025107128f89a3ee894d16b89b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:32f6dc7cbecffd8e485dc3114fdfca9aafa552218ef10135432dfae4b587e400
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:0350d15be6e919f367e616ac2c1e3351bbe7f8ba0ac4e73716e29b3f05c68589