Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 19.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.3-debian-dev, 19.3-debian13-dev, 19.3-dev, 19.3.1-debian-dev, 19.3.1-debian13-dev, 19.3.1-dev

Index digest:

sha256:fc3206fd81a9e85764bcff2e65e122e25a4a1855c32a05290f59e1dd2b71cdc9

Manifest digest:

sha256:fa3d64905d3f3b6eb380ffe8da6fea6b2269237fe212d6ecbdb94c083a873819

Size

91.04 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
12
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:037e9967cef44446b0ef284dc76e93a0c46ce1400bc619d81a6f7e9690db692b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:eab45c2bd689ff8ec52754ec5ecd86f07a0d9f99bc817a91aea9124bb894d41f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:705ecd4f9c17a6c84be24f705b2721275d09bbdc89659f71a16ccf996c3bdfe5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:29aa0b2a880bd300c40c0fd587da2307382c15a05b28eaaeacf957edaaff56dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:6a219e00d3d56fffbaa42bbaf2019da786a4f1ab250e2bf302310f1764580d22
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:608addb7fe48f7d13bb67fa132d2cd622a9e1a2dc7e743a136350779d63e581f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:21e87f12212c850d7ab80dc3bc0472944f7ae2945c6a67401fdd25fbb977b3f4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:3201c99de5db1e87a366642a73e754b1b340b25bccdded34835f8dbcc1664871
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:2c3b70c81b5a7d1936d7b4898fbdb7009eab0142cad84a3dfb16ec75d45bb57e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:495777237e0e640f454d11d2c1713a0b9fbd09784e442bddcaf61334e437d29a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:69ab0b97260dd6e8739b1d47a5518b2888038aa977e7cfd06bfb93330aca8ef1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:56d82bf85bb05ad34a485dea69b7f4f9e77009707065d3f4fcd40f314b1558e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:959dd32b050c67fe25ec5258e676cf32cc19c938e00178c3db3e1231aa55d040
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:d91402b7f8dc007468b91fe151e0ff7bde6e7771bfe920dbd6ea15c7f7e51753
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:c48c5e2eb5dc0e2f1063213c0d3e0d82cefa23e2025ed945e7a75cc02bf442d7