Sign inSign up
GitHub Actions Runner

dhi.io/actions-runner

GitHub Actions Runner 2.337.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.337, 2.337-debian, 2.337-debian13, 2.337.0, 2.337.0-debian, 2.337.0-debian13

Index digest:

sha256:8abc29276f6c48e15ec55e5613382b468eaad1dd3b547b5981784dce6284afe7

Manifest digest:

sha256:d5ea894d16fc7a8f4dcc6545774fe5910c2f474c80d3af0b9c9aafbf5d0ac1c5

Size

246.90 MB

Last pushed

6 hours ago

Vulnerabilities

0
4
6
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/actions-runner:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/actions-runner:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/actions-runner@sha256:89f998676a93b58f84e469a10153f14309e61e975bee1708ee12b576a05ad8b1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/actions-runner@sha256:c67a2834ceeb6731ffabfa8b0e23180914699150d35d8b66dcf5fca47c1d5899
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/actions-runner@sha256:807de3efdbd76a5599e38c97a7d6ac7492bd78c107d8e2805a177168bf08df9f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/actions-runner@sha256:e92f923e7cb1f52a9f16b13aaa61f087ed57cc6fbb3f27b7ca85831b9528680c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/actions-runner@sha256:ddea7a3027b4d4ce6b507d967ae039a8ab6374b4966e0fde0abc5eee008b40bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/actions-runner@sha256:0db93e2de7852d01474a43443258455dd5465d74c0db7ed6c61b4a08f8759ae3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/actions-runner@sha256:021c3cd354f483e0af8cf181914f23dc897771f523e9a65ab01812a0e0161635
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/actions-runner@sha256:9574a2f0fcedaac958ed17cf74c7bdc8b329383d0394610da09259baf3944797
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/actions-runner@sha256:d67934ff15b6f6188be2c3d07f56f25223235dd5f485b3a8a0746844372ea9c2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/actions-runner@sha256:92d866a777dbdddf417e6d745406f5e96aae31055e89c155127a0ab91a412c9e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/actions-runner@sha256:2f6b2c1e17812b822ee1f65cddb12a2e9e18ff0df096a62f79ff55adb3bbc2c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/actions-runner@sha256:f27d2cd515aec4779364b072c362e5ca086931174538950aa7fff4345516b36c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/actions-runner@sha256:c5248e3259128aa854b2ae8c8f7b99c49f134dc8f8fd963459e8a05d3032931f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/actions-runner@sha256:19795685355a34b48f8b4189188e2c27fd07c2f114978c872913d9be9fca9c19
SPDX SBOMhttps://spdx.dev/Documentdhi.io/actions-runner@sha256:3d563b47ba7daaf4e157541cde855a1438f7a5058c1789eb67e98fdfe0185dac