Sign inSign up
GitLab Runner Helper

dhi.io/gitlab-runner-helper

GitLab Runner Helper 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.11, 18.11-debian, 18.11-debian13, 18.11.4, 18.11.4-debian, 18.11.4-debian13

Index digest:

sha256:4f8a5f60eefc83edbf11ae6eeb6b5d8dddb54460ae028aac01443aeeb49a3f71

Manifest digest:

sha256:8d58af203aec06eb34808fcd94a9fbf93dd8bd9484a8b3ad53b0890e9b842080

Size

53.23 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner-helper:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner-helper:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner-helper@sha256:15730267f328c334e11b19c2b3c37b2483df10c71d338c15184db47a91152e1d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner-helper@sha256:a77f244fd3e52549f58ed3baae63e9d2b3c6b10f6927263feb2aa19ea3df49fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner-helper@sha256:71e6b521927c85bcd3daa37a15e1f4a61483ef19a0e4682c3f5512a8820b1f13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner-helper@sha256:719b185371ecb98ad831f220cc13a70d4ace606da9d71560cbd85019bd3abd2f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner-helper@sha256:67185a882d975988e1b3addd289dcc9a4530dd93e56f0bda45ab74d51448b7ad
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner-helper@sha256:29ea03daa0bb10dd1c201254fe8efc7cfddbe467144a6761522e8eb34730578a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner-helper@sha256:d5418144e4c0376c83d047d9a9d438a6a64686f3d89a713e0f1db0239594c144
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner-helper@sha256:3634a642af05d11dc5b476effd8fa1128805695b84e990ee336e9fbbcc91a906
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner-helper@sha256:77151ca1821b83b9d93381e0fc6c046433221ae3bc27fdc30901600150056b17
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner-helper@sha256:9ea3ade66affba3b16b0c5f77434164dda4359437a89f620ab729c8ddc2b565a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner-helper@sha256:d2b71634891b191bfe62acddb86277062116828dcab0bcb00613106cba3d34d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner-helper@sha256:fce01e21417c3591633a2b353218590c86bd276e1b32ba91926bdd40f44e8a5a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner-helper@sha256:4a88e919604f7f8a3aa5f49181937d65000b03f440cf2049ec959a96ca75c98f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner-helper@sha256:23741bcadd25ab5e4c09463608a392000e88945b436e18ff72678c949c142ed3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner-helper@sha256:cd135affeb459f1161980d227a565bc1cf3c8a8a07b45503e5201b0826fcd4c0