Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 19.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.3, 19.3-debian, 19.3-debian13, 19.3.1, 19.3.1-debian, 19.3.1-debian13

Index digest:

sha256:cad742ac796822b27d50fa7f1310319999aa79f64670410b88a1e49a4d9f8f58

Manifest digest:

sha256:e1587b1849daf1788f7361fff6e72da7971908c4ccf144531feea63217c718a0

Size

81.87 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:8e2383255c7861be732503957e9d3c40014b2c2ff0dba85fe69c5bdec7e73f72
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:7c2e3d84089bff201bc8031068996c98c4646216217488cbd46d173a97d2e083
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:dbe92ed3546fb242fe64a92900161fdd1d0e7f7f5abfc9d032ed432096f77662
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:79576c5005e5a01de287b742e6eedd478b0ffdca8e3b064bdc2b2671f160d7c4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:bc68ecdb5cff1540887507ed3a1c21d6e699f78175f78d5e34647e8ce0a0c199
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:7220c193af9b7ff865e2f98bc203e285013b852b1ea625436db7ccfc0285fcf8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:78cd134f69b75ddaf49ff4d8b9023265d1958871d86fc1e4aa251b5d1f11e00c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:0b70edbec0bfff554a07590f801d2e5342585cf0641c7a8e8bd0d6a39b16cc58
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:4761f736f2af2a523a89dc9fe6644805e6b14875f66fffd6012e13d464991a91
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:4ba0b1f8bff6678615ed6834e01f45a18e1071d3a45d04da0aaa2748b42114f5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:a0402d1e63136233a111cba5fc621807c0e0bcb605e991dd8ba23d3859d6522a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:cd036b9530b696290032d20a8a696d31817ad29826a4e45fce8211c4c34f1fef
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:51392aa7f56f3da14c13643324b907accc05ace736767ac6a11ed1ca13e5cd81
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:3667285ce0e760cbf8fd0256603b991652c32d32f9bb5df4796834968483fbac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:6b1590277e424eb021b434578f07d1b1f9a7498494f2421fc98c10df2888cf96