Sign inSign up
GitLab Shell

dhi.io/gitlab-shell

GitLab Shell 14.57.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

14-debian-fips-dev, 14-debian13-fips-dev, 14-fips-dev, 14.57-debian-fips-dev, 14.57-debian13-fips-dev, 14.57-fips-dev, 14.57.6-debian-fips-dev, 14.57.6-debian13-fips-dev, 14.57.6-fips-dev

Index digest:

sha256:126ee9c3bc47320025d83e19067f1709df54db716b1de62a2daebab2f11fd5c8

Manifest digest:

sha256:59bcf93e88eef40f588462f67b1151816747e82e969d72b5a0311c6383d6b3f6

Size

98.12 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-shell:14-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-shell:14-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-shell@sha256:4065795eea0c83f8b61e2c5d2e7a5d9debd0046ef66da58f38023acd442c25a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-shell@sha256:6c1874bc3c2140eba1bb28bc3fa20e3ee897cdccc01d09085622ab1dd6590808
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-shell@sha256:3a92a38b1cb08678be53dacce244debf82d22afa332987601eb589144379336d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-shell@sha256:06542f80c58cf4f7f957abe77d07c7bfdc5a1613d60ff0de8f9f58d084b8c041
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-shell@sha256:098fbc64c01f000260ce6648994c3e80a7501b673db5fb68baf1f712d8aaba57
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-shell@sha256:5b922f94565fa889f70773d097493a05b1ced03bf5c77a75a7166c7b836e7d1d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-shell@sha256:0282b3f932734b38ad452b83eb2a0f725ba98b3b12e161be2f0b7d574e1c9500
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-shell@sha256:48a0c2c6ba50412b704de40405fad352f4beae71fa1a5cf64bd47fb178f57332
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-shell@sha256:fdcbb3144afb60705f58832387bf31d3891967c0a7945050bea9318d40d7da73
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-shell@sha256:c6e8b7380670ee2b11a0495c2255f3885412c52c984befd89a8017292be2fefc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-shell@sha256:cfd958d6b50bd3f890cff9b5124f3b1005d1f70cd8828a6490b8f256c424535b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-shell@sha256:2f1d40e17afffd211f86696384c12b603af6b0c7dc6be84d48a6973df8078cd4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-shell@sha256:957408963a875e87c72132868a557f353b773e05a3a08c1abb220b0f9c88aa69
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-shell@sha256:8e12eb51f9b903aa48f162387e2329aeaf421c7d8f535f023337425869356054
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-shell@sha256:e174e42b67ef7fab4e9ee826b43e152ffd86df83c41324bb24ae89f65c2a9120
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-shell@sha256:88487282e81287c2e975736463f9a785f6f0ff948f18ee93574a29f42da1186b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-shell@sha256:453423d120fc322903aa33b3f078e25e95edaa83aa94a37e8f460e4f25df8559