Sign inSign up
GitLab Runner Helper

dhi.io/gitlab-runner-helper

GitLab Runner Helper 19.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.3, 19.3-debian, 19.3-debian13, 19.3.1, 19.3.1-debian, 19.3.1-debian13

Index digest:

sha256:7d378f184d3563911c868a1bad3d3feb6b8002122e2681ad8c3173a9e407a11e

Manifest digest:

sha256:deb31ea28ac26e35acdd7d649e4e48014debd5f5467e4665b01af86678f14c6b

Size

53.52 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Oct 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner-helper:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner-helper:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner-helper@sha256:cdddd56a12150f98109253dee40d104d52c32dfa3a740c325aac97906434d55b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner-helper@sha256:fb71f6f0b696735fea88317b0529f953a574651ee8bac9c719ec0dafda46cbb2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner-helper@sha256:056e5dbf8cf190503134167ea81d6debdf404cf226cd36ed72e51ca8fe7ddb60
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner-helper@sha256:dda8f4655e0209413a11133c56ca398e93e2e974dc5ded47a20cc0c5a5157ac5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner-helper@sha256:9fcf62cf05b4f79bfb42a64be30ac26ce9c8232e8c2857a4e6fde9e2d9f3999e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner-helper@sha256:8faf9fa285863b881d19e560d9ced234f1dd50812647c864c7d24167754364ff
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner-helper@sha256:fe6a89eaeb275a6c7226f0b87de4900b615e34a5aad976ce3d4e5e342b296d0f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner-helper@sha256:b93aa1cd595b1a5af712bdbbd06507c3d9da12b45d42ad2109472256041ee42b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner-helper@sha256:a5490533673b344d765619f77136d93573ec354de836b7a6fca1b4f3783d485f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner-helper@sha256:1b361256fe2499348ed2642b75e68562818552b6ee6eed6fe4b638fa1fadceb9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner-helper@sha256:77369f3c3230ddf3c7dd4d924c9c1d222b4da7665f1d4da7cd1eceb0d48add79
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner-helper@sha256:3535637189f2f41ff31ec792b53dc04d941f133dd865cbe6e895f4f6f08cf437
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner-helper@sha256:180ad979fba4d487d95478deb4720701d51832ebbf2783ea152ee241f2c2adf5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner-helper@sha256:9f9343fd4755d60ac792ab761cda21ee3435fd37f76133b482ffe7225e39ecb9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner-helper@sha256:41ff9c7ef8bdffc7fca0d264cde348feb5aa07a1b39a083ebd2751032513d459