dhi.io/gitlab-runner
19, 19-debian, 19-debian13, 19.3, 19.3-debian, 19.3-debian13, 19.3.1, 19.3.1-debian, 19.3.1-debian13
sha256:625a48a8bbd49aea6ac838f3481225474f4dbc05d7047f8cd9dacc5bf106ca8e
Manifest digest:sha256:6b8c03c194b3667057d9d53ab5ce55b1a7a7bae8b7036dd9edd11c7be887c9f2
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-runner:192. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-runner:19 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-runner@sha256:ff4eae8eb6fe2319a9574221b302bb089f9b3537a58063f5e1ffee5bcaf4faf0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-runner@sha256:3a992958758160eae756d430bdc9f2911a5c70ec9ff8e0882d8cd13bb437bd62 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-runner@sha256:3f3d736a45f2e19d6341507db6db71614f49ca35f0a8d58cfad00d4b034d92c1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-runner@sha256:8983c823ef25207fae24af0bfa866868ad891fcdca10b1d47902c0680df33e57 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-runner@sha256:1c98681f31f04fe5ea109655c8ac9bdd3a6671b326f60856cdc1fb8f27884a3e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-runner@sha256:45e0a90c8f5c28f1f879fd4b217785e87c5cf4e4ef6d8f771a9d5afdc537b808 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-runner@sha256:fad26f1113eec7de02a6761124372a112fe6b63f6f25c7f7d115b6d9f9a7dde4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-runner@sha256:0e0ee916e8e8cc0ed05ea0196177d05bae6d57373d69acd5a623746298fbb8d4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-runner@sha256:4065122c9feb764e9605ddb4b6b8f3d9412a92ca54779c54050969054a004e03 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-runner@sha256:886048ddc1cc11e36ff40a7e8dad46a77c1e69658324c5d500deb7d606887cdd |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-runner@sha256:38eee5b32bbd6feb1ff62c6b2aceea325ce27bdbc52a9322ff2ec909598ccf64 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-runner@sha256:213900d1f9e0f010ad27e90a89de86e93eea34ff36ec83559252c9deea0e565f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-runner@sha256:598cc058633a404584c4c512c8287d65f7383e15a66a32f432be93282210295d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-runner@sha256:bd144fe1b9ecc4f8d29051a369250e8286fe8f2dee0380ad0941a1fc42c80474 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-runner@sha256:e5695afcb08536c67b2c0c72ce1f084731984d6e0ca6fc33ddef5e420614c060 |