dhi.io/actions-runner
2-debian-dev, 2-debian13-dev, 2-dev, 2.338-debian-dev, 2.338-debian13-dev, 2.338-dev, 2.338.0-debian-dev, 2.338.0-debian13-dev, 2.338.0-dev
sha256:a2af600a20fe058caf6470f1fda88119afa63a44a6a1d310f7487067ed74f44d
Manifest digest:sha256:59eb5075f38417ad4e04737e06c0a5a8376b69cb5ebd7105cc5e91f3214581d1
Size
256.06 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/actions-runner:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/actions-runner:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/actions-runner@sha256:1d154ad10de47307884ca044acbafb598afc59bd5e406afc170549b4f8325c34 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/actions-runner@sha256:c728936b90750b34a99df767d9171ade88589b7d54c0cdffbc1305e920fcf8cf |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/actions-runner@sha256:eacf961b9cea797f39273d0dd81f86cc5323e69c17a09fd75dfd51bc35ebc6f6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/actions-runner@sha256:3c2e7eda0b8df55454703d95e0db148a9d5f1d8bfc84ecb2b34e65237bb7c329 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/actions-runner@sha256:92bc876695fedd3afbeb33ea73cf7616d31b31b9dfc5402b5c8cc1f31dd01e5b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/actions-runner@sha256:72579b585b0619e8ffb6d224c39cc44bdfafe6dd7414d49329be44c74da96965 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/actions-runner@sha256:e4cbab0003f1f9cb389ac08c6753feda6583cc6ffe8dc123d32b747aa11395e1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/actions-runner@sha256:825d75593749edd856c1d28032440bb6a54a2c47e606b24aa08fc430bc46c1f2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/actions-runner@sha256:d07ea129f03d623465cc192a8d412ebec94b5d0dbc3a62713ef5f98e1549f250 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/actions-runner@sha256:308e6a2fdf0dd39aad623add9b00694cc2b0e81fa116fe5e6d51bb7c046cff98 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/actions-runner@sha256:65a3a1bb9d17dcbcc258b5efcf74b5193274c359d3b9443209d51495a356bedf |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/actions-runner@sha256:43178bf2cddade9515521812b90cc8914425e79efb7122b23784cd8600c511fa |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/actions-runner@sha256:3a5451461d7480bb77792cf65449891fe229f75d3bf3ec398cb143a777f36c80 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/actions-runner@sha256:62c4e2e04854a5ae309ae9051e92b49fc21b83bc8918988e7849137cbfa9bc9b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/actions-runner@sha256:ebf22f344d51da407d0be29116a85c3c77886dd66de2f0bb57c8a04bbdc4c961 |