dhi.io/actions-runner
2, 2-debian, 2-debian13, 2.337, 2.337-debian, 2.337-debian13, 2.337.0, 2.337.0-debian, 2.337.0-debian13
sha256:8abc29276f6c48e15ec55e5613382b468eaad1dd3b547b5981784dce6284afe7
Manifest digest:sha256:d5ea894d16fc7a8f4dcc6545774fe5910c2f474c80d3af0b9c9aafbf5d0ac1c5
Size
246.90 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/actions-runner:22. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/actions-runner:2 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/actions-runner@sha256:89f998676a93b58f84e469a10153f14309e61e975bee1708ee12b576a05ad8b1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/actions-runner@sha256:c67a2834ceeb6731ffabfa8b0e23180914699150d35d8b66dcf5fca47c1d5899 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/actions-runner@sha256:807de3efdbd76a5599e38c97a7d6ac7492bd78c107d8e2805a177168bf08df9f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/actions-runner@sha256:e92f923e7cb1f52a9f16b13aaa61f087ed57cc6fbb3f27b7ca85831b9528680c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/actions-runner@sha256:ddea7a3027b4d4ce6b507d967ae039a8ab6374b4966e0fde0abc5eee008b40bd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/actions-runner@sha256:0db93e2de7852d01474a43443258455dd5465d74c0db7ed6c61b4a08f8759ae3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/actions-runner@sha256:021c3cd354f483e0af8cf181914f23dc897771f523e9a65ab01812a0e0161635 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/actions-runner@sha256:9574a2f0fcedaac958ed17cf74c7bdc8b329383d0394610da09259baf3944797 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/actions-runner@sha256:d67934ff15b6f6188be2c3d07f56f25223235dd5f485b3a8a0746844372ea9c2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/actions-runner@sha256:92d866a777dbdddf417e6d745406f5e96aae31055e89c155127a0ab91a412c9e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/actions-runner@sha256:2f6b2c1e17812b822ee1f65cddb12a2e9e18ff0df096a62f79ff55adb3bbc2c1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/actions-runner@sha256:f27d2cd515aec4779364b072c362e5ca086931174538950aa7fff4345516b36c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/actions-runner@sha256:c5248e3259128aa854b2ae8c8f7b99c49f134dc8f8fd963459e8a05d3032931f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/actions-runner@sha256:19795685355a34b48f8b4189188e2c27fd07c2f114978c872913d9be9fca9c19 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/actions-runner@sha256:3d563b47ba7daaf4e157541cde855a1438f7a5058c1789eb67e98fdfe0185dac |