Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 19.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.3-debian-dev, 19.3-debian13-dev, 19.3-dev, 19.3.1-debian-dev, 19.3.1-debian13-dev, 19.3.1-dev

Index digest:

sha256:ae7c63dcafab9e6eae72860ee75c02240a83a33b273d9e8fc3f530e929ad5c40

Manifest digest:

sha256:1399e89257c99cd3334e2e61ab0125eeddbdde17a7e3008ef2113d164987649f

Size

91.04 MB

Last pushed

3 days ago

Vulnerabilities

0
1
0
11
1

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:ea59a7ca60651cca5fb58ea416259e8dbb0b8cbf48840198d65d10e8f54ead8b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:23c889411944847f93eea33a276794ccdb1912798016fcbf8cbc6b9d2eccccce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:48354c0128308407889186c63752a5872f488ef20262ad283a3689dddd13326f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:f8afd0db20998362a89e5713a826aaa4121fd474069a9b24e468f9699aa0841e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:d4860d6ee1384befa5b3f624b00e83b48f29c19463027a0dc0d71f40cbc8d092
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:454e144ae759eaff9ce9a91d192e43de043976f28b688393099a4bf054cebcf7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:3c0a4f2eb4b9b4630c67ecc0de2b9e927193c80f6285316790ff18683ee9bc0c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:1e263dbf5d41b1031b567396e60d989fef5b73d19b9069500faaa43e585bdbec
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:e1c34074173cb512d53e60673efc8cd348fbd14a7dbd799e4cc137a73b4215f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:27662023b5ff6052d785663ced6fc11b4092dc28fc4384941fcc709775d5daf5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:4fedd76c8743727a369c172cd4456b66a916e41c18ef02d741b7af47c6fe0561
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:ae3815ebf7f580848b78b74edd1c5d76b611082c2b7bce9dfcb0469bf822395d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:3b583b266f80659e042b376f0152665839f036394944c9d20bd913e22f7f163a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:a28c770b61c8a57d46823616fab34e29ff066e4bc130086eea6935dc56a24a57
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:35b2521c8ba956706b8249bf83a3d3dd1c934e4ec2bfa45e535ad0e2cc42c116