Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (dev)

CIS
linux/amd64
debian 13
Tags:

18-debian-dev, 18-debian13-dev, 18-dev, 18.11-debian-dev, 18.11-debian13-dev, 18.11-dev, 18.11.4-debian-dev, 18.11.4-debian13-dev, 18.11.4-dev

Index digest:

sha256:995585aec91e6d5d419be7b61e7eb65ba2411850b873a23eda1d8e79c60179b2

Manifest digest:

sha256:ad0fc649c05763778cfc19df6dd1f052489041a3bb09af63a0e7cefcdfb98686

Size

89.98 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
12
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:509a03347753c5fa41f6c5d8d209880268f082b8614ac1d8e42d4e27cb889dc7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:60d3bd5bd3f83e3bbb985cc769cf07d091663389deb4a941af3b8c6cd6c4f1ca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:2fb83459d65f81608833482bdfecdd75d920896747285e59c02575b124c9929e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:26a3fc4003349406fe7710d9684ea421d497b892f3577dc8abd1e815e7b67292
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:8881ca8510d29e66f797274b3d45d18eef2a20ab604dd05e042e51a9c8b6a680
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:970c5c4d96c46abc71e854ff1f0e6bdca8ddb1d1f59295b04cffec5bb1d93412
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:1f63e065e1706aceab77623742714789c47cfa47f1cca6f6e10db96571ddaa46
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:54f051910c1302ec2cbb19d3aaa850540531433d51806004bca32a39067a714a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:dc40c8aa84d8bb2b3675957b2416dbb0fbaf3ab27d2e802b7c5bdcd437ba0e7c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:e6f4aa6a69b53e77c47ba1ffaad2c31222c63d6349f1a54c988fe77ed380ddda
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:40e4e2aa8ef76157d948388bbb9b1ffd35050d4c369fdb419f59d05d24c1adc7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:77afb659f34537627fcdd3052b090c97ab32bd5e841a5628bbe855a2e23a588f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:33c566a3467c713e516d5117fb362469f8685903dd02338a9a340224778bf64e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:6e8ba12534e82150d6f79aab5141ebf8c0f155574ef30a7a2f32eece2fbec7af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:5dd727dfdc5c83cf2facfe8fba9c89e8e8e5251a5877f6cb36ef225fcde5a60e