Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 19.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.3, 19.3-debian, 19.3-debian13, 19.3.1, 19.3.1-debian, 19.3.1-debian13

Index digest:

sha256:625a48a8bbd49aea6ac838f3481225474f4dbc05d7047f8cd9dacc5bf106ca8e

Manifest digest:

sha256:6b8c03c194b3667057d9d53ab5ce55b1a7a7bae8b7036dd9edd11c7be887c9f2

Size

81.87 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:ff4eae8eb6fe2319a9574221b302bb089f9b3537a58063f5e1ffee5bcaf4faf0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:3a992958758160eae756d430bdc9f2911a5c70ec9ff8e0882d8cd13bb437bd62
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:3f3d736a45f2e19d6341507db6db71614f49ca35f0a8d58cfad00d4b034d92c1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:8983c823ef25207fae24af0bfa866868ad891fcdca10b1d47902c0680df33e57
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:1c98681f31f04fe5ea109655c8ac9bdd3a6671b326f60856cdc1fb8f27884a3e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:45e0a90c8f5c28f1f879fd4b217785e87c5cf4e4ef6d8f771a9d5afdc537b808
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:fad26f1113eec7de02a6761124372a112fe6b63f6f25c7f7d115b6d9f9a7dde4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:0e0ee916e8e8cc0ed05ea0196177d05bae6d57373d69acd5a623746298fbb8d4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:4065122c9feb764e9605ddb4b6b8f3d9412a92ca54779c54050969054a004e03
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:886048ddc1cc11e36ff40a7e8dad46a77c1e69658324c5d500deb7d606887cdd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:38eee5b32bbd6feb1ff62c6b2aceea325ce27bdbc52a9322ff2ec909598ccf64
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:213900d1f9e0f010ad27e90a89de86e93eea34ff36ec83559252c9deea0e565f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:598cc058633a404584c4c512c8287d65f7383e15a66a32f432be93282210295d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:bd144fe1b9ecc4f8d29051a369250e8286fe8f2dee0380ad0941a1fc42c80474
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:e5695afcb08536c67b2c0c72ce1f084731984d6e0ca6fc33ddef5e420614c060