Sign inSign up
GitLab Container Registry

dhi.io/gitlab-container-registry

GitLab Container Registry 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.42-debian-dev, 4.42-debian13-dev, 4.42-dev, 4.42.0-debian-dev, 4.42.0-debian13-dev, 4.42.0-dev

Index digest:

sha256:bfeab43e8df2a2f2d8f005274835d026b266c8ea91e0eaf8deea6f81a22b739b

Manifest digest:

sha256:65a03d21a40ed7fcab7be08cd814b785364c98f77897f6aa3eb0d7402562f5cc

Size

57.79 MB

Last pushed

22 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-container-registry:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-container-registry:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-container-registry@sha256:1eab01d126de2f1fb3e58006f430b6570f1630c2da19eb42ce3964b847c62d97
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-container-registry@sha256:79ca849741a06a4dc8886b0dc62bced40158d8006165e32d757b9ac097704cdf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-container-registry@sha256:5648dee90fa79f682cb26e3921a7410fe88ce358dd94d7502f3f0a4e85bb2730
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-container-registry@sha256:16b4812b30c293bb62ef220360cd04f30ca39405dcd57b64998abfa3c0bdd34e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-container-registry@sha256:7841ccec0dd33f6339d888bdcf8aa7a4f691554bcb59c6e38262d61a7bd8a12f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-container-registry@sha256:163490353d04c4167be23ca5e719c463d44993eaa379df0cbf1ef71d318a593c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-container-registry@sha256:c31b474874673d53d1ef124ba51d95afae539f68e391c7d6a754124bcc5c6e53
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-container-registry@sha256:5157f4cf7ce8ae11cfd9a0dc8934900e55dc9a1511105736e2c41544e0c5597d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-container-registry@sha256:7ebd237a2f8ae7cc2f4eeec5e760d75a602f213dee21a381f26ad74dc82b19ba
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-container-registry@sha256:9d3179fa3aa73a56ddd627c04d4f5c6352e4c57ca5adfea6343b382fc2d5a497
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-container-registry@sha256:a9a9712cec5862a402c609eeaae7df923f4fce81fc73d9fb36d51c76e5810854
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-container-registry@sha256:d40055d74f27d7774d7ca3bfe18bf39abe2a1836660575a06164e649596f31b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-container-registry@sha256:eadf7539e518451d110b9e34f954902311a41e4761d61e09745b44114f2f9dd8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-container-registry@sha256:70952a7ab98871a7301f0ebf0d185d893de247844f6292f6958b770420db1230
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-container-registry@sha256:20d7d5c45cc9192fba76e584a4468e3bde66316f28e65579b40a64299f027034