Sign inSign up
GitLab Workhorse

dhi.io/gitlab-workhorse

GitLab Workhorse 19.1.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.1, 19.1-debian, 19.1-debian13, 19.1.8, 19.1.8-debian, 19.1.8-debian13

Index digest:

sha256:b7465065b4979624f3c58b27a5d0cfb09529eaaded5eccc229bebb4f91e2539a

Manifest digest:

sha256:61951418a005d8d0760bc5badb4607e19ce95aec19ec029d4d927e6360d7ab70

Size

314.10 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-workhorse:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-workhorse:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-workhorse@sha256:367f81b196be96dc4b568e2a495d18d71ef7d6c4673897dfb7197a032a5414be
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-workhorse@sha256:e7472b38e336a462c014e782838c2b917016c28bde91a8587f5c4dc7e1fc0532
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-workhorse@sha256:56cb4b4378f2f3dc576b77f4180a7cc037a9c2507e46662c09291fc755dc8f46
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-workhorse@sha256:2f3b03237d48ececf85b245cf1245cdbb79b4d843af7d599560ea84cde25a768
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-workhorse@sha256:209ce657b35347d696cba3c9ed2fef184027c9f71910c5795bb71393490244b0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-workhorse@sha256:69642bfedfdcd5b8e2b22a76999d70b186b799744bb15cfe73f37e6782e410d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-workhorse@sha256:c90aa844d170f2696aff8f7bc2471d53e1e180686255d479da3e5034b814dc7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-workhorse@sha256:75e498c31e8c3aa8b4bdb3bbc8afc493e125343ba2e792e8ad8597d2aae6882e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-workhorse@sha256:bc099b99a8c75a76fad78333ef0c98e17821f5c2b2a1f370e2ae0e51b03674cb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-workhorse@sha256:9607d5ffdd6ab397de1da11ad7a3d29d27fc59748bd647eae8b5539765aec64d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-workhorse@sha256:0a5742a77090a3db08cad704e20ec38bcc28bd3f12d07f5a78db3ebaebf0acca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-workhorse@sha256:8b3a65b39dc6fc5673ddef6cca6bd231290360abd3d815a38a6f8944db8f8776
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-workhorse@sha256:bd24e4ea47876ca2785cc0fe8312b295c44bd555f68aff19dcf9d33bc0980359
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-workhorse@sha256:aa068532ee76a2c1569e1920834763da8cb51876e04d046838780886bb87a16c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-workhorse@sha256:55c02ae05f3c072d3bcbf66ed38200695b5fb57a714fee535fb0906c860ec174