dhi.io/gitlab-runner
18, 18-debian, 18-debian13, 18.11, 18.11-debian, 18.11-debian13, 18.11.4, 18.11.4-debian, 18.11.4-debian13
sha256:76a545348c229acad5bde349f2adc50acb94a3c9797aa125b2d6b49b5a2d8e23
Manifest digest:sha256:9a09191642ccec520db082437ddb0ffa942822dd3bbc575b3d7492278a89fea5
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-runner:182. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-runner:18 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-runner@sha256:5d3f0b4c9db41dabeea06f700b9bf79034c43adb50d57c4688bda7eecf16542f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-runner@sha256:a571816c094db5441d55eeae224127dd4056935a2dd6e0b3b37ea51e2e8b87be |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-runner@sha256:1d9cb2aec1e81b96739a1f64db860a62199d7be09048446d3987066eae1af83a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-runner@sha256:836b5508dbf26a24bfe9a4cca578e323e798a83ce404130fc253298fbe3b548c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-runner@sha256:6eb80a4eba52fb74fbb69859384126acee08b4fad88b5410fc96b8a85c5b57d3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-runner@sha256:23f7d494c81f14858f13763aa4e86a000a9f10436c598cdf7dcc51a1d8033951 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-runner@sha256:ceec71c12bad1630f231d1f03f6896763218b661ed9ed65b8dd30f0cc0a0c2e7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-runner@sha256:29a31b298d9f0328da08159dceb9cfd76f05141543e217fb615fc556dfa961b0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-runner@sha256:bd18238d333987e7d470385af1a2b415805315d818e325735bafd6f423dd7a37 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-runner@sha256:2864239bb4735c5a91a5dc7ae671b263bfef521ac3785f78411419214437f8b6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-runner@sha256:71a8dd58bee5c3caaedbd2c5930b6d49ec89d6f1da8cd3ee9df5fd9322026246 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-runner@sha256:246f998853e9f440b17e4949a92459f508eca9fa91ca506288f56f1bf7f29a28 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-runner@sha256:0a28fc5a60887980f1380a44a39fd3d59d37412f9f3719be9f99363aa5e3cb2a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-runner@sha256:909fcf449069b505480faa69b8d1c5e51abc95b42db6d29c473d4fe2eb7d5ca7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-runner@sha256:2811059b8559aee16d607dae788ce7851871053f057ade13174545b75267b315 |