Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.4-debian-fips-dev, 18.11.4-debian13-fips-dev, 18.11.4-fips-dev

Index digest:

sha256:3aaa4ce880ab8f5836c79bcf0a310934ca1ff75c6f09bae88c6155eb7c2db7cf

Manifest digest:

sha256:96a1dfa88558d24bf9e7464d2ccb04cc88bfb6732bb97c6a71ffe3d40296166b

Size

90.73 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
12
1

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:6da162f5e9f08f7b73ae09e4f65fe90b4a20a9db4eb95d85a670bed9ec1bca90
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:6451358aa8d04f2bd99cb953d5a14df22ea051ee8b82b4d93a32db96287075e2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:f5b9aaefda8484c804c529f86061f3f53d4a68be1acf6a93d9eaa6136c41a17b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:42cf314eaf78db1cb19077d5c96d2efc306b99240515714db0c466c749b17287
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:c8f080e85303ff5a5f2cdff738e0df300110dc28527eda9b518edb0d78bf3f1b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:0907f5188bca89bcca0470d8449873f1135bb02e1df492754be2f22d652d2a00
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:e52a0b07e9b3a49d8be59be85c9197f0a7cae9f20aaab0da8a0af99c39f59fa5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:61091bd84c2d87238a4e25361d694ed2ce961b388dc570b5a7c4210ef971f9e2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:53649176cc44c07edb96a8f1e0098a5fdb880f6586774fbc9950d99accd22a6e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:1a075b9bfd45b287b14f2d0fcf0363ba3edbda16ae776d00c38f8578ddb914a6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:c14b2c5764008a00323499e01056b58db8d40be776f63e59a4ca159f80f3a5e1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:dac8c336c2a732c0e41626c15441eb31990917e1021a0fc59a4f6c99c2028ff2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:36434d1ef0c6f515019882720f988252f67356842ab416f02512c0639a6bc0cf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:8fb62f658e1e622986cfc820d868aa4f77e38b450aeae83f51a1b492ffb39ca5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:7802cb111c532397cf416e679990e849cbf18f9dbd8100060cd0d820fb5b4e30
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:7227e7e85fa1e0d8b5234baf9c11e17a3f570c2aeceb4e25ddd5cfae07f6b309
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:8553f4a37df650122c40ea05013ea99a3a99d03f73a72585e80f9156c6717724