Sign inSign up
GitHub Actions Runner

dhi.io/actions-runner

GitHub Actions Runner 2.338.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.338-debian-dev, 2.338-debian13-dev, 2.338-dev, 2.338.0-debian-dev, 2.338.0-debian13-dev, 2.338.0-dev

Index digest:

sha256:72ee39d98f7a3659ce2a1bf9b570dcca57b7c46b433c325929055efb1f48ff13

Manifest digest:

sha256:96bfb7fd3b13283e12407ca363810984f2189e2be2832b68096f3b0057eb2f94

Size

255.47 MB

Last pushed

8 hours ago

Vulnerabilities

0
4
7
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/actions-runner:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/actions-runner:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/actions-runner@sha256:c7a55b85e023c99f59843d23d6289ffc10e841f0c7a6b150181a9b48ad92657c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/actions-runner@sha256:7fd3dc7e386cc99423252a0be5cc724cd6312bcf7eaf7d08072bb2b351abbdd3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/actions-runner@sha256:a66c6a87c50f920ec24ddecdc64459a921ce91b1f7a084fa084ef8123b75fef2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/actions-runner@sha256:dc32ec2c9b11be131f778f58f515cde9ea81bc776170179dbd0f64c76308f651
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/actions-runner@sha256:cbdac4ca56ce56ecfdf00ba1ec31e4d448a80273cf2fc84fa90a292ce47787c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/actions-runner@sha256:781edca1ad34b5fa3d26d56feebdd30ae0b400049481e65a4e7900745da2a648
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/actions-runner@sha256:95ce7cfb4eadbbfc778d26d27c4c4d79f7b8a5e0c5b9016c3ab46db6fed502ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/actions-runner@sha256:ca0707d13b9bb05bdb7c93bbcbb3b93a90b382120d578eed69ed7ba385c7ebd2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/actions-runner@sha256:9210789fe94dbb6aec0c8c4137930740b59bf02539e65c33795c7dbd87f30d4c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/actions-runner@sha256:9e1682b61c78182fdf80fa2526ce36755584c69880fbad38b7297ecedf8bd4f2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/actions-runner@sha256:7aa2ba282a593e4829f321aefaea0e8f4b606564cc3164bd10a37fdb14e00c9f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/actions-runner@sha256:51d4d576417b21171973d8aacf13f11240ef42094fcc4bbe47cf0468d4961f61
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/actions-runner@sha256:9150695726f8af031d61665c472eb9d6da9253e9090790b475a2d4fa4df3fa4e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/actions-runner@sha256:c5efe11038dabfe117c0d48f457ba328e666944e1fc7948792ba4a4e4c5aa83d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/actions-runner@sha256:4351566c3784cb7e5216ad88b6cb20b9d416cd9987e688ab2473c8247a559dd5