dhi.io/actions-runner
2-debian-dev, 2-debian13-dev, 2-dev, 2.338-debian-dev, 2.338-debian13-dev, 2.338-dev, 2.338.0-debian-dev, 2.338.0-debian13-dev, 2.338.0-dev
sha256:72ee39d98f7a3659ce2a1bf9b570dcca57b7c46b433c325929055efb1f48ff13
Manifest digest:sha256:96bfb7fd3b13283e12407ca363810984f2189e2be2832b68096f3b0057eb2f94
Size
255.47 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/actions-runner:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/actions-runner:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/actions-runner@sha256:c7a55b85e023c99f59843d23d6289ffc10e841f0c7a6b150181a9b48ad92657c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/actions-runner@sha256:7fd3dc7e386cc99423252a0be5cc724cd6312bcf7eaf7d08072bb2b351abbdd3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/actions-runner@sha256:a66c6a87c50f920ec24ddecdc64459a921ce91b1f7a084fa084ef8123b75fef2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/actions-runner@sha256:dc32ec2c9b11be131f778f58f515cde9ea81bc776170179dbd0f64c76308f651 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/actions-runner@sha256:cbdac4ca56ce56ecfdf00ba1ec31e4d448a80273cf2fc84fa90a292ce47787c8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/actions-runner@sha256:781edca1ad34b5fa3d26d56feebdd30ae0b400049481e65a4e7900745da2a648 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/actions-runner@sha256:95ce7cfb4eadbbfc778d26d27c4c4d79f7b8a5e0c5b9016c3ab46db6fed502ae |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/actions-runner@sha256:ca0707d13b9bb05bdb7c93bbcbb3b93a90b382120d578eed69ed7ba385c7ebd2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/actions-runner@sha256:9210789fe94dbb6aec0c8c4137930740b59bf02539e65c33795c7dbd87f30d4c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/actions-runner@sha256:9e1682b61c78182fdf80fa2526ce36755584c69880fbad38b7297ecedf8bd4f2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/actions-runner@sha256:7aa2ba282a593e4829f321aefaea0e8f4b606564cc3164bd10a37fdb14e00c9f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/actions-runner@sha256:51d4d576417b21171973d8aacf13f11240ef42094fcc4bbe47cf0468d4961f61 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/actions-runner@sha256:9150695726f8af031d61665c472eb9d6da9253e9090790b475a2d4fa4df3fa4e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/actions-runner@sha256:c5efe11038dabfe117c0d48f457ba328e666944e1fc7948792ba4a4e4c5aa83d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/actions-runner@sha256:4351566c3784cb7e5216ad88b6cb20b9d416cd9987e688ab2473c8247a559dd5 |