Sign inSign up
GitHub Actions Runner

dhi.io/actions-runner

GitHub Actions Runner 2.338.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.338-debian-fips, 2.338-debian13-fips, 2.338-fips, 2.338.0-debian-fips, 2.338.0-debian13-fips, 2.338.0-fips

Index digest:

sha256:fdf2829003103447256911a67710e959cd0fbb248fae237a4fb09e7e120104fb

Manifest digest:

sha256:6a7b0dfaeaa4478b01671d86606b9592d2f52fbebfc2feb1b282950f298b31da

Size

250.08 MB

Last pushed

12 hours ago

Vulnerabilities

0
5
7
2
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/actions-runner:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/actions-runner:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/actions-runner@sha256:953db4030011b60e297b9915989ef446732ee5fbd29ef15ec728ba6476494f65
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/actions-runner@sha256:897b4b30bf5521768568ea3dffdd94bfe4f3d114b90f6d939ff7f25e350ac03e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/actions-runner@sha256:92e2140f9ff3ea42a372d543708ebe7c7c7f5e97320e4676d9dcd5aecd4d2b0c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/actions-runner@sha256:c8d247c671ef777acb2d05f4f115319dbe3ffb8b33795f3483804cc220203da4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/actions-runner@sha256:ae7654159e2252ff199b8d991f58d099ab6b93a2ce4c11748a0d797d65a4e017
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/actions-runner@sha256:afe99374c0c0aa533cba42684cb620feac0fc303ac741a65c6518759e258d684
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/actions-runner@sha256:96874038afd86426e8369de8930ce601083d1389039fbcbd2d6870a4c1834419
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/actions-runner@sha256:e4efa5522b5107ce810356a37fe46da256056fade8c9cd162330a24c9458cc11
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/actions-runner@sha256:c611dd6e88da2f067c0f12131ccce3bb7ba3902cc98468ee2acf73fa970f26c0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/actions-runner@sha256:8e1bf77fba41eb8df02148da8ed8ecd6d57f546d4b64d55002ec33e0f523f66f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/actions-runner@sha256:8688a007194de010fb2e60eac970488aeba5aaf3b608bd5113f1be1323bcc069
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/actions-runner@sha256:0c0b1b699961136ef4d22487f674a4b6130f3a679c2c3ed29e431b65dc581ff4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/actions-runner@sha256:38b574a2f8c2dfaf26e42a0245eb9df7718da9c16b3d499f38e4fe8db67fc3a6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/actions-runner@sha256:846dcf6351c670b4371f240c8f3de9130de2326a5a0e5687c3205f0a35b46f0e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/actions-runner@sha256:b8a801e6947a15bf9017458479167395c7d975752f5f53eba11f9fc849d157aa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/actions-runner@sha256:83a4ac123fc58e837b5328b01247338f201de3feefbb88b9c6335d2c61c246be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/actions-runner@sha256:4725e5aed8f34e0ef43c390621298f356aaccd6752deb911dd7d77d5c1decbdf