Sign inSign up
GitHub Actions Runner

dhi.io/actions-runner

GitHub Actions Runner 2.337.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.337-debian-dev, 2.337-debian13-dev, 2.337-dev, 2.337.0-debian-dev, 2.337.0-debian13-dev, 2.337.0-dev

Index digest:

sha256:885d589e60c6d198671475036369fcd2263e0aea19fa69f3c7249b15f65f5b33

Manifest digest:

sha256:fd97330cfbafeedbd33a5ce166db99458130ae78ea455450f55546a95ecd0f19

Size

255.07 MB

Last pushed

19 hours ago

Vulnerabilities

0
4
6
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/actions-runner:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/actions-runner:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/actions-runner@sha256:c1d029b644fc36669add1e2e0cc2b3891b051453b9924b51824f038893da948f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/actions-runner@sha256:594248e248595534b07a7fa7c33fb5c0d9a9a167811770b224bef194c4e776cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/actions-runner@sha256:37901708cc6fc936c102d9d7e9562cdbf91d86a4524d62afe47d42372aeb44e9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/actions-runner@sha256:021a6d9c2f966e399ab816809d07ad5cde33a8594cc515968531cdf18ab8c684
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/actions-runner@sha256:b24cd41e76cc6ccd0e0958330645aca0fcb77ec1ad7f485c74db716bc466302c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/actions-runner@sha256:43b1f635242aa6417de5cacc28f7c747a192526924625eec80dc0d96351d5abc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/actions-runner@sha256:51839e58b73330db349d0808ee9a57771d0218891b27bff39cab09df4e877e8f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/actions-runner@sha256:16164bc49826bf535eb2c3d5d82ef1d40316e3cecad5fad5a56fd1e511701326
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/actions-runner@sha256:7ae587d7de27964c27cacf6650047f906ff26ef29250b1894342424394aa09ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/actions-runner@sha256:c7bf03ce2d3fb66fd8c66c599bf1c0aac691637c5330a3c190bd4f777d4b6acf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/actions-runner@sha256:c7fb5538527a46748fd0e61b4398e98e670e78676b09f6c1fb1158bf62f59ea9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/actions-runner@sha256:47adea490804e6eb278c758daeec59e4e87398bd53be98077b992532fa65ab2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/actions-runner@sha256:13a3a6b21eaeba2673074663a84b5ccb5a1fa66bc325a64594e7b3b292a899e5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/actions-runner@sha256:de45c143ddb1ea61bd5657880253873549d18530e5e5c8fe47bd24604c17e595
SPDX SBOMhttps://spdx.dev/Documentdhi.io/actions-runner@sha256:33f6626509c81a3c9d9b39316ec0ff47bc66ac5894f08510e2fdaea3878912d1