Sign inSign up
GitHub Actions Runner

dhi.io/actions-runner

GitHub Actions Runner 2.337.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.337-debian-fips-dev, 2.337-debian13-fips-dev, 2.337-fips-dev, 2.337.0-debian-fips-dev, 2.337.0-debian13-fips-dev, 2.337.0-fips-dev

Index digest:

sha256:c28b8a694ec0e9a4bb3a7b1c8889abdf14cac95f9e4b8cd622de58bfbc0ceaf3

Manifest digest:

sha256:e8e04d31ed1338a3df9a8e5910b0f1062ed8417ff4d80d74b7f676fdde997298

Size

255.83 MB

Last pushed

1 hour ago

Vulnerabilities

0
4
6
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/actions-runner:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/actions-runner:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/actions-runner@sha256:789b2d99c6f33ae211069b35ab7fe0b086321db159f70f650f4c2dd43d451659
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/actions-runner@sha256:62a28dfb0dc4a4c7f2798e50fd3a6c4136c66690b59fbbcd10fabf76d16e0036
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/actions-runner@sha256:6cf5e8afa2ba32a9f090a67023e623e2f098ef3ef37e1b302cab2dc57d46ea9c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/actions-runner@sha256:952e304a29db96b68cb933f665f91e2e5b9b868ce86597bd6850ec493f78fdbe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/actions-runner@sha256:c5414379f0fed5f58b210bf61f8e467a054ddd90beee35f6c07ff7fb06129f92
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/actions-runner@sha256:63c8fddc3ede88132ecbd5b733135cc8e7fe0544d10bce1602973ec3d45ec061
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/actions-runner@sha256:22e50aae594d398b51c48588aeb0f39bed3d7c3c3393d25dbd1fde2b6b0941c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/actions-runner@sha256:cffdf490d8ce3d28b084a3eacc6e0dc1f3ef1eda1a831c6a5e946645c73a5a74
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/actions-runner@sha256:2407b98422aa93f482d3a11d9559601b7acee297492faadb214484c18578c0eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/actions-runner@sha256:5e4dc0749063b888f4ce196f360ddfe1a4983cd715bdb5b0cb1b859f04d14458
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/actions-runner@sha256:0678a71561991537be7cb5f9214f69511a79b3637bb42d3a75f7db7e4a4785f2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/actions-runner@sha256:61bb2a68b4757c6c29fa8115d131af254a0a375922dac055b874e42e15ebbf81
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/actions-runner@sha256:894ee9797bf0d7476acdd0523e07e481b6d2bdbb54f59ff30728938a60fdb148
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/actions-runner@sha256:3e9f8862da857d940fdbc8198b4caf198999c11c01d75ff8c9724cbe8468d8cb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/actions-runner@sha256:e7b2af65733d027aff628e430dec01477888c4cb4a1bc7ceceedf2f4e42e8871
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/actions-runner@sha256:2fc131a1a61600d0d7523b3f5ccabc87ebbb0ec202dd371f869d5d3c59011c0f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/actions-runner@sha256:7defb5752b9b88b1863243a2994727889529ea586d3e774b84b080b602b1590e