Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.11, 18.11-debian, 18.11-debian13, 18.11.4, 18.11.4-debian, 18.11.4-debian13

Index digest:

sha256:925f782fee400285f886bdaca8bef6c97f556479e9826458746470b10f277ac4

Manifest digest:

sha256:9edeb301cdfcfb5197588f5ade4484c6852f1d903772f65fb307125c2edfa8d6

Size

80.80 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
11
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:ace2d0c546f1b21696f757863e644e84bf870077b7878b220e62927687f2a873
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:3e51b019a0fff74c314d025e2f54fa7dce1415d65bc18c797151c4340c95e6dc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:0b08754bab317cc258377b2092fbc03145a00ec26229c95f5a0a050003578d21
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:e75802f85daed80d8b0cd9d500d670f5eb5e61ca670da3ad90e50101614c3a80
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:13c645461b91aee8ec1b61fe891de72d330f9061ac3ccf9e7e42ea787975b68c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:3834c1aaf65b26ab09316d438966e7b9bdcfa8e5532c688fc59f7dcbfb8d1191
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:66cc2a280790571408885cc1ed4ea4fb2068f9d78a500447da563e2fd50731e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:81b4351fe3e6b030144f33e5538063718992f7db88f33c4776a9ecdbdf72bd3e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:7885b366585a02e3d3fe3f953e097bd8b6cd7de3813a0f6f35ad3de68df00156
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:37829503f4362e7c2048493db04b3cdf0d6aff57a3fd0098d088b0d8cf2cfaaa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:e45b10afcbef1ded5a882590c2ad260380343c89e6c04c2d70aff5946e6a5698
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:418ba4043622f16c2dc61ac3c96fa53f59fe34a0bd783178a73ba3a6c195d79d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:043d3a8839ebbba81bd460835f100a766e65241e29ecbe5997ce9e01bd776f7c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:df092d0949b689bea4d05260433421fee62cc82114dfe209166163a17039b9bd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:15475b34f55ea35d2883eabdd5548db718c857c9277f899af936bcf03ee25b70