Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips-dev, 18-debian13-fips-dev, 18-fips-dev, 18.11-debian-fips-dev, 18.11-debian13-fips-dev, 18.11-fips-dev, 18.11.4-debian-fips-dev, 18.11.4-debian13-fips-dev, 18.11.4-fips-dev

Index digest:

sha256:3aaa4ce880ab8f5836c79bcf0a310934ca1ff75c6f09bae88c6155eb7c2db7cf

Manifest digest:

sha256:96a1dfa88558d24bf9e7464d2ccb04cc88bfb6732bb97c6a71ffe3d40296166b

Size

90.73 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
12
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:6da162f5e9f08f7b73ae09e4f65fe90b4a20a9db4eb95d85a670bed9ec1bca90
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:c04deeb383460a0f0c8dd26a29a1f5ae6c397ad86efec8e03f4e0eabed4401ec
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:f5b9aaefda8484c804c529f86061f3f53d4a68be1acf6a93d9eaa6136c41a17b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:dbf1ffe6dcc640188b3c9d1c2303a674c7a62765c1494df28b93e3501b25ffe1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:383c764b5cd57e44e5dcec9022b2497a4467f4ed25ad8fe78565caee7cad9c64
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:6dfe639852245cf1bc0d757815a396b902ca7a2c471dceb05d64ae3a46fb4781
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:cf9e2014c7ec85e20ac85a33c402e8e21e389aa0c3581df7d22ced72e7c94372
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:61091bd84c2d87238a4e25361d694ed2ce961b388dc570b5a7c4210ef971f9e2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:53649176cc44c07edb96a8f1e0098a5fdb880f6586774fbc9950d99accd22a6e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:1a075b9bfd45b287b14f2d0fcf0363ba3edbda16ae776d00c38f8578ddb914a6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:4eeb015414a7f84dd859ef7c41dea45682be00259d00194aaf7538c726a0a9ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:750075e56cb593bf73cb92b9f95801c6274257b6fb22c3fd11a76f5ccfb8dae9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:8dd331803b8172215a2a9b7fae176025588a3f6bf18cc417581b4813b77681b4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:8fb62f658e1e622986cfc820d868aa4f77e38b450aeae83f51a1b492ffb39ca5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:7802cb111c532397cf416e679990e849cbf18f9dbd8100060cd0d820fb5b4e30
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:7227e7e85fa1e0d8b5234baf9c11e17a3f570c2aeceb4e25ddd5cfae07f6b309
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:8553f4a37df650122c40ea05013ea99a3a99d03f73a72585e80f9156c6717724