dhi.io/gitlab-shell
14-alpine-dev, 14-alpine3.24-dev, 14.57-alpine-dev, 14.57-alpine3.24-dev, 14.57.6-alpine-dev, 14.57.6-alpine3.24-dev
sha256:ad560a4c724f7208e9bdf33a598592295cad2adafb8771dc25c39e347d53e5c2
Manifest digest:sha256:96478e4cf9aa502a03bcb2d1a99ce538cf1f31bdf4dd6e006e7a48fd81780fe8
Size
76.14 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-shell:14-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-shell:14-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-shell@sha256:510ce5ced1e9c6d4b751fc3315976e4da88da8ee5a1558e702207db1944ef541 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-shell@sha256:f0bdf54303f4830e8ae2df770d56fccaeee82eab772a511a847534b7cfe33ae8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-shell@sha256:11ab874c1500fff281ef75ff5ac717a094e708a90258ad7b309af1f397193bac |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-shell@sha256:be630020541668b164e52a01fc748043b986fd8d8a78b64c5c52e92a12cc6623 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-shell@sha256:c2df375ea2c5f7f3ccf8e30e8884b736d3b5601818b49af6ffd578bcd44421a8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-shell@sha256:e96cf0fef11f44097f625a8063889d8be79fcc3c8ccd4b76bc370196358e79e3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-shell@sha256:3ddc8aadf7cfada63337786b9236ca3ac718680e843afb6c53331586bfd4d4d4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-shell@sha256:bc2d1b3be1d584aec30ae4fe392dce56d37ca1691941494fbccfe09a1dbc9b4f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-shell@sha256:dfda58b07cb68ffcbad414d3468ca523f1feb7311fc7827673d95b428e0fb184 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-shell@sha256:db673f570fae97ecad409476f4031ffaa02ca3b2f0794b641c85413e04ee40c5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-shell@sha256:7e06dd31b21bc69f39a2b57cc02dc0894087732f56c58eaf100a7c670edde9df |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-shell@sha256:8a70536079769929f7cf0a93216662c7ab6dd5b2f757fe962bdc6019920bb4d3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-shell@sha256:b8646522012af4fb986eabf8e72ea11b8a04c6a32d10cf949e56eabc859efdd5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-shell@sha256:2ae8c24d5d740a51e96c82ee4313835d9ff0a2bec82c1e5cfb5c00290879b62b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-shell@sha256:94ce55ce1c819d1eb3fbf6ded35d97cb1ad15bf1f22644d042e83a5719220a94 |