Sign inSign up
GitLab Runner Helper

dhi.io/gitlab-runner-helper

GitLab Runner Helper 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.11, 18.11-debian, 18.11-debian13, 18.11.4, 18.11.4-debian, 18.11.4-debian13

Index digest:

sha256:41bb832986be43172a1ce07ac2cd092c2891b9c94bfd10e61fe93c167cc1fbe6

Manifest digest:

sha256:7b5c77c30fc90db56ab3fbcfc769ab317e86cf4d200d9ae2ffcf2a199e271f00

Size

53.23 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
2
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner-helper:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner-helper:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner-helper@sha256:8d94b40184f2fdde0da674d3c481c3fd3c9ea00a6d08f97c36d1a9cff056dd16
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner-helper@sha256:4b2f434e0dca7d3391116f0e83727b4da0de66a2ac2686a3aa0d7fb9405324de
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner-helper@sha256:a04db92927b6a7b602380842b5de579301b4b34672608306d922175757183953
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner-helper@sha256:6984beb90c0e1e488777624a369d6b4dec4ca9f30cdcf75b4b437df778c04a11
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner-helper@sha256:54c98d3b90e640f2aeb26e5a0331082eebe8f7201ed922855873165eba23f41e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner-helper@sha256:29e61bccda955d9cc0e0e13c3469ff403dce827624925478e1136046f30de270
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner-helper@sha256:3f8f4ecde3b903a55af4430ccef55a7f5f01006d2ca1684608ca11713c569090
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner-helper@sha256:f3716859f1eb3c73342752e065962c104364f7d127295a13ba9d704554d60cb3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner-helper@sha256:276d09c9356f6874eb019a604b725e73dd6aae4aa3826409b2eb772928486b77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner-helper@sha256:eb152e85e06c328b85261eb2e1f28b18bd1b8fa824c9a631fc6ce109d2417d6c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner-helper@sha256:af0fbcda133d8d7e1c6744bd5170fa3c1a9761881a46c9c41d80030cf946d45d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner-helper@sha256:9fe27a16595289d708b4d8ec33fb37ef1b6d8f7884ec2c3afcfca428c22b5765
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner-helper@sha256:5c20f640bf7baa62761328bd10345573af26c1c503673ef6d705dbaeb2167061
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner-helper@sha256:f6eef3f7118e6a7e2b96a73fa21b19da8f247e2bfea89a1b180646c2bf7be380
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner-helper@sha256:94949684570c01c980c5cec8765c6d2965b637c34e3368aba38f6eaf0c564c03