Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.4-debian-fips-dev, 18.11.4-debian13-fips-dev, 18.11.4-fips-dev

Index digest:

sha256:1327ae7bd115223f21a0981387709d4ddd0902fe918d90167280e0c9b3303df4

Manifest digest:

sha256:4eb4c3a6cab595f6116ba9f18cfa8b766aa68488e3df913a5c022fa1865ea049

Size

91.10 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
11
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:2efe3abee9d5dfdc7a62ba0239c5d05e8d2df65c2fb5343077c1b2e5bb3f53ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:761f8c90fb7bdcd6cbbf59e2098b48c2919105f26bc830ce165f316b616f26b8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:b942d66d95520288c72ed5ebad22d2031b3d14a82de1290c365cf2052498743b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:d2037d1cadc4f8c72eeaaba106f8b68884e1e0e593fd4ec1ad902a8f9d01018c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:28de624dedff65cadcaf24f61b40051b0ceeadc1bd63f5bf13b672ce088e34ac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:be0157461a7b688ccf6c513ee69eeeb500d5b50b98abda1982bc65a1abc2b037
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:65a820a6a643371728a33c649b211764826ba93b0c26eda44f72bd668dd1a589
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:e4e475a088c568d09b0cc48abd6b10b2de8b920de077a00432f263ed4ee889f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:5f7c1743a9c4116abed29f6759f3ca2aeda7cf040738c9e340c0c88cad69864e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:a33037cd341914b973b2cc11137f6f180c1bd32360b287b227fe71125eefc819
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:23f077447d58a637c503992f62eedd0cab5484d9a04c22656874568c48fc3044
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:39b08953cdbbe5c97b9e56fce2304c7f5119c38da3437bf08f67a83d812d61c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:96ecac30f3938ad071e130ac53345d08295ab88c1b54e12efdd1e8296088c751
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:d5e1bb68d1bdde7c7bdb7406811ccbf740f068452fe23bf3406afa1e5d9f5a0d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:0f2874d941a2c134acde05413850209dbce5857797372a8319b9284d47cb200c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:6890ae82adce53df05e27071b1150ce46a23d41eeee47bff1428feb752b91c84
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:b58ff74534f4ca575d1af5425f725a13fc9f5f5529122b3026b3d6b78cde6494