Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.4-debian-fips-dev, 18.11.4-debian13-fips-dev, 18.11.4-fips-dev

Index digest:

sha256:bb11f5119ef725d7eb9bef2d822a2640d47789774da8dce96c29282feb603ce1

Manifest digest:

sha256:ce4f60c47c7d53a9ed3ca8f3dbacbedc3894f536ae716a2a245842a982d5b193

Size

90.73 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
12
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:cd55b82d00e3570c9c24a607a503444f573312362fcaf0602c7af544b1ee548d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:74466f93828247ec8d98a4f0e69b7003356d82edfb7fb62068d01f87e7dbf729
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:bdf88127352a24eeaf7b403de685ca379ea69475526e6670908f2db8729ec8f8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:8a928200dbf10893f3ccdb59279186bc52ef5d1e6768586ca54ae5905c840dee
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:c5b4bb411c742171e4bb5396178ecf0cc4f3c86844bfb618cf0f1f6bfb5bd558
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:7dffc29a10e9328f1fd7dc7e2118915ed59f47506e23e31951346c545ec21fa6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:8fbb48084d51809fafc780086cd10e68a76aef62920c85866d4b20a460689f14
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:1024131c2483dafb5923031ad76a82a697a7067c3c616749cde3e0ef7aa5ba09
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:e7acbdb9c4dcd54f2fa9ce67f66e7223d261553d22f57e5255bee0c81a5a5fe2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:0f1772d339b845317a1334f5724445e700865877f6c64a33e5ef9dcbda69146d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:b167678daef83780b7a21fca54d09ade4c7b61d7483fa0b72d521eb5fef16845
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:97024bfcd66f29d6bbdbc1814abf4068394f4e0fa6c8f89e30dacaf724bf0b93
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:5acc5fbc8ad542bc79b790135f8bb304740857270bcf19f878adff370094f026
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:a7b17fdcb90a118697e01c10fa86be3a136637c359cb64c5b311995445bef080
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:594cf723ede1aefee6da8102751d85eacbd253ebaca84d6e847570efe8fde426
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:a31716fa77f2bacbe95dcbecf5af1947edca4118e1035bcfb9df68f5bd11de17
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:9baf17540ddb64bd1573b0028019c9432c0d9d96df79a55acc2ed46a390b1619