Sign inSign up
GitLab Runner Helper

dhi.io/gitlab-runner-helper

GitLab Runner Helper 19.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.3, 19.3-debian, 19.3-debian13, 19.3.1, 19.3.1-debian, 19.3.1-debian13

Index digest:

sha256:3beb793c58788e7e651fb44c99de1163749c9a8e615c21cdaf15cc60046bafd9

Manifest digest:

sha256:d571040dba8e314820ff42144282d2f54ff64c1cd7bb2bde75abaabddfb71b7f

Size

53.52 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
1
2
0

Support

Ends Oct 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner-helper:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner-helper:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner-helper@sha256:7d6396a143d95deae91681d39e49922ca89bb84e9e0b5756f599ec308aa47de5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner-helper@sha256:cbfc33f9e85acce97a156b145d1cf378289b41e01b805cf85dde75a3c2161046
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner-helper@sha256:dfb5e4215e63b4b60bb676846b2999f900cc8ee871b630c82199d01b1de3fdc1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner-helper@sha256:5ffd3b975cbee44a88206f04ceb739fe8cd6e92ba10e41d3e261323745396eb7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner-helper@sha256:5edd0a864124d15ac7ecdf3427c857b9ada3933bccc0d20f60506fe5d171c01a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner-helper@sha256:20085a06d70c864733f79667bf8b45ae68b9d7b5e34dbdfc578f75f49f1e09a8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner-helper@sha256:908f567257d67e87da8a5baa1f75fb739f4c97559e7288bf61bab24a59462cd4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner-helper@sha256:e01c8d0ea12325a1728bbabe0b83fe49ad78a205a3c1c7de1be989ec885f0cfd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner-helper@sha256:b44b3995353f830386ad06b5ce0c5cf1ce62d76287995c2c1406d73b7bc5e55a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner-helper@sha256:497bd6cf1ce73a5c715abe2ac6a879b4bacf3356a050d4c96dd33c1c4c8e5a96
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner-helper@sha256:87ac2652f428adc3df5422e07dad69b8338bf86828d60fb362f66b86e360e8d2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner-helper@sha256:7c48392aa24d944c80cdfd58296869444996d683d17167bdf8cd595c71d9d752
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner-helper@sha256:ce12e58a016ed9b0504bc847f41491069c1bf17ee461d3a426163c7ce538e2da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner-helper@sha256:95e578b4219558fa35df9f2de2bbac709c95ee4ef406166fa51f3fdc8accba03
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner-helper@sha256:907929ce1e9c3164f74ab8d20858f709d8d3545e14b4f47611647262245487b9