Sign inSign up
GitLab Runner Helper

dhi.io/gitlab-runner-helper

GitLab Runner Helper 19.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.3, 19.3-debian, 19.3-debian13, 19.3.1, 19.3.1-debian, 19.3.1-debian13

Index digest:

sha256:2cc5a15c7b230f53696a3ea934dad554c741b5cfd45542d7ec803581fdf51836

Manifest digest:

sha256:39db7d0f4c880f136c52c1ff401c9619a8b91709a6ed7dd008e034e54cd84248

Size

53.55 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner-helper:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner-helper:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner-helper@sha256:5f8ef4c27de6a86f7dd6ce6dfae4f53e8882dc91983f48cef8117cfc3f1861aa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner-helper@sha256:7de7d23c2254c5a46a7dd9625054741fff0f380e306861194f80ad930518561f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner-helper@sha256:f96820e7cc64ce4173c40f37374ce89a15b23df7b06256e3ee1500e0a7098baa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner-helper@sha256:6407c664d6fbc0d48b7485a6a8c8082b9e6c6b469f79abba240fbf9d0d6104e7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner-helper@sha256:2fd5e41efef3832c6687a5bee6a385662284cb21f6e96f64693171f68d0442ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner-helper@sha256:e5f469043f9752b81dffcca29f16d878c042eaabef657173363cc71f32fb38cc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner-helper@sha256:47590e1a34c8400f7e22d63f957d8c8d7edaed726df3c15c40b633b26fe54487
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner-helper@sha256:b397e4b40be3ac23131bb0b2459a04c388d070cd03cb70d03940fb0510c2c200
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner-helper@sha256:132a39ef85972c95145073c2ff67a5d454e55239f869fc92dc00ea6aa70ddef2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner-helper@sha256:6a6382d0553c8016ea64384138ebcc4d3914c744b88f3e9f4ba2b92096402e6f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner-helper@sha256:9974c80682fb3bd5922549d756e3a4b8ef7e64f85ccfbd4c5c80914aac44d301
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner-helper@sha256:858f00d75a62e76d3c9fbd94ffe13631ddc1d411dc596787084ec8aeffc543b2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner-helper@sha256:4993dc743f89379b8dc6568a8e6dc380c10cb38a1117947c1c0d7022fa9a7fa0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner-helper@sha256:28218b68682b6c7f91607fa0e9561d81d021ab60f17ac64837ec7a3c21bbedc5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner-helper@sha256:8f666a7c15d79ea23baff7378107f1cd69319657bc8a53857fccad2ba046595c