Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.57.x

CIS
linux/amd64
debian 13
Tags:

14, 14-debian, 14-debian13, 14.57, 14.57-debian, 14.57-debian13, 14.57.3, 14.57.3-debian, 14.57.3-debian13

Index digest:

sha256:f76ffe64efe383b81b1d1deeac3991114c311ac5dc8d85eb9cd08cb0b9731374

Manifest digest:

sha256:4b261e264381db33483cee6debe7ae7b005122269a1dbb205ee5d2c2d2ce9ecd

Size

85.94 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:3dbcfa6b9d975517bbd2687a1667d6a86a50110f079197c458e5d59e6269ef38
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:f9d17a6714af2813f54a9248bae43c54b5a375966abb4d359b1472078a92a6ae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:92f69e277eb7616d1fe5dbac6c66ba79a1d5de8c6382313a277e7c7a90fe4f03
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:895fee0b3c8e618bfe78750e806c38d279e1ae749da472a0746329e4a2e24c4c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:ae9ad377ac211e264160ebadc7405fc480b145fcc2ac629baafb5268b1fe8132
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:9f45025cddc46aa8f6b3d0459e57b6520e0bdd1ce22e0c337382d8b56fcab944
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:61d787088fc405ab8e262d14335aef3aac0564c594ac3b21b0c6c967a417f8d3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:aff9b1c8f09409da5260915c268fda5fc8eb7c97f40b826d4663d14bdfa8b2a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:77c440a7f5d78dce960d5ccb23909f8e135838bf75fe5fd6839cc6a11dfb8d95
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:2b0ccd4c8856fabcb9db5bdfcd9a63123866f2c277e8d7862c5750884cc0e123
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:68a5b28c940dcabd9e7229bb9e1ea3ba88d75e406874e0c74e3cb1639668a777
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:9cce96e15e248c757fc5fa68b0d1cf711f6ba42f5fcea9f3f647a3b0aa32221c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:9bf49ecad6e7ff472cb0e6fedf0400d4b6b754769c20e9d43b7974908197be94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:5e541eeb0ef72e429b6e68b669ce8613244e37e316753534838491fdc0404297
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:a46462be087058d48346be9ef2e345a61bed58678431f09315e58e83a83be183