Sign inSign up
GitHub Actions Runner

dhi.io/actions-runner

GitHub Actions Runner 2.338.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.338-debian-dev, 2.338-debian13-dev, 2.338-dev, 2.338.0-debian-dev, 2.338.0-debian13-dev, 2.338.0-dev

Index digest:

sha256:a2af600a20fe058caf6470f1fda88119afa63a44a6a1d310f7487067ed74f44d

Manifest digest:

sha256:59eb5075f38417ad4e04737e06c0a5a8376b69cb5ebd7105cc5e91f3214581d1

Size

256.06 MB

Last pushed

3 hours ago

Vulnerabilities

0
5
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/actions-runner:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/actions-runner:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/actions-runner@sha256:1d154ad10de47307884ca044acbafb598afc59bd5e406afc170549b4f8325c34
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/actions-runner@sha256:c728936b90750b34a99df767d9171ade88589b7d54c0cdffbc1305e920fcf8cf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/actions-runner@sha256:eacf961b9cea797f39273d0dd81f86cc5323e69c17a09fd75dfd51bc35ebc6f6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/actions-runner@sha256:3c2e7eda0b8df55454703d95e0db148a9d5f1d8bfc84ecb2b34e65237bb7c329
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/actions-runner@sha256:92bc876695fedd3afbeb33ea73cf7616d31b31b9dfc5402b5c8cc1f31dd01e5b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/actions-runner@sha256:72579b585b0619e8ffb6d224c39cc44bdfafe6dd7414d49329be44c74da96965
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/actions-runner@sha256:e4cbab0003f1f9cb389ac08c6753feda6583cc6ffe8dc123d32b747aa11395e1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/actions-runner@sha256:825d75593749edd856c1d28032440bb6a54a2c47e606b24aa08fc430bc46c1f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/actions-runner@sha256:d07ea129f03d623465cc192a8d412ebec94b5d0dbc3a62713ef5f98e1549f250
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/actions-runner@sha256:308e6a2fdf0dd39aad623add9b00694cc2b0e81fa116fe5e6d51bb7c046cff98
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/actions-runner@sha256:65a3a1bb9d17dcbcc258b5efcf74b5193274c359d3b9443209d51495a356bedf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/actions-runner@sha256:43178bf2cddade9515521812b90cc8914425e79efb7122b23784cd8600c511fa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/actions-runner@sha256:3a5451461d7480bb77792cf65449891fe229f75d3bf3ec398cb143a777f36c80
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/actions-runner@sha256:62c4e2e04854a5ae309ae9051e92b49fc21b83bc8918988e7849137cbfa9bc9b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/actions-runner@sha256:ebf22f344d51da407d0be29116a85c3c77886dd66de2f0bb57c8a04bbdc4c961