dhi.io/actions-runner
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.337-debian-fips-dev, 2.337-debian13-fips-dev, 2.337-fips-dev, 2.337.0-debian-fips-dev, 2.337.0-debian13-fips-dev, 2.337.0-fips-dev
sha256:c28b8a694ec0e9a4bb3a7b1c8889abdf14cac95f9e4b8cd622de58bfbc0ceaf3
Manifest digest:sha256:e8e04d31ed1338a3df9a8e5910b0f1062ed8417ff4d80d74b7f676fdde997298
Size
255.83 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/actions-runner:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/actions-runner:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/actions-runner@sha256:789b2d99c6f33ae211069b35ab7fe0b086321db159f70f650f4c2dd43d451659 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/actions-runner@sha256:62a28dfb0dc4a4c7f2798e50fd3a6c4136c66690b59fbbcd10fabf76d16e0036 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/actions-runner@sha256:6cf5e8afa2ba32a9f090a67023e623e2f098ef3ef37e1b302cab2dc57d46ea9c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/actions-runner@sha256:952e304a29db96b68cb933f665f91e2e5b9b868ce86597bd6850ec493f78fdbe |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/actions-runner@sha256:c5414379f0fed5f58b210bf61f8e467a054ddd90beee35f6c07ff7fb06129f92 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/actions-runner@sha256:63c8fddc3ede88132ecbd5b733135cc8e7fe0544d10bce1602973ec3d45ec061 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/actions-runner@sha256:22e50aae594d398b51c48588aeb0f39bed3d7c3c3393d25dbd1fde2b6b0941c7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/actions-runner@sha256:cffdf490d8ce3d28b084a3eacc6e0dc1f3ef1eda1a831c6a5e946645c73a5a74 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/actions-runner@sha256:2407b98422aa93f482d3a11d9559601b7acee297492faadb214484c18578c0eb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/actions-runner@sha256:5e4dc0749063b888f4ce196f360ddfe1a4983cd715bdb5b0cb1b859f04d14458 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/actions-runner@sha256:0678a71561991537be7cb5f9214f69511a79b3637bb42d3a75f7db7e4a4785f2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/actions-runner@sha256:61bb2a68b4757c6c29fa8115d131af254a0a375922dac055b874e42e15ebbf81 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/actions-runner@sha256:894ee9797bf0d7476acdd0523e07e481b6d2bdbb54f59ff30728938a60fdb148 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/actions-runner@sha256:3e9f8862da857d940fdbc8198b4caf198999c11c01d75ff8c9724cbe8468d8cb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/actions-runner@sha256:e7b2af65733d027aff628e430dec01477888c4cb4a1bc7ceceedf2f4e42e8871 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/actions-runner@sha256:2fc131a1a61600d0d7523b3f5ccabc87ebbb0ec202dd371f869d5d3c59011c0f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/actions-runner@sha256:7defb5752b9b88b1863243a2994727889529ea586d3e774b84b080b602b1590e |