Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.11-debian-fips, 18.11-debian13-fips, 18.11-fips, 18.11.4-debian-fips, 18.11.4-debian13-fips, 18.11.4-fips

Index digest:

sha256:ea10f46e38615db512a7bbd1976a1bd8b4c3bca7e636872eaeaf4e712b214fc4

Manifest digest:

sha256:0dcd86fcaf2fbe12ea87bea53048738eb117be04674a397564f7a3f94ee74121

Size

82.90 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
11
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:3ddbc89439f99befde06bb581fd5ad3a9fd4c669c33019a62cad6e1d9f204ed4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:fb08133932d53a1a680b3fea0b1bcc66a3abb74d292600f38df1b2953ee76c94
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:64d8596b4399cd3cbb1e80b028fe4bc7a4d0be8033ecaf5490e71f26da291422
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:cd39da5c986a2ad380016a45b416023e5ef034f95684a1249ac67f77b8ae4fe7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:53d2df330d894cb3a1b3862f8054b78179102bc3a042bedac0b1770a1a69a76d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:5f2b0934a4561d5122a2a6dfc73d2646a9b561b4220114d37526e1cf76302ccc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:d0654ddfb7cb7c96b56481dce1c15a3695081dae22cf21bda9df28c1cba56f7c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:6084034bb457ece0ca8e9dbecb4f02b65f18a37e014d9e70cc9cc6ce172c5bcb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:7d06f5283fb71f336b1b9875aa6cc0c96ae90a5d89582a119cd93c8436ca1e08
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:f2bcaa284e9972e650fffd9645eb227b5c878b3b899981d4890376fc283c7aba
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:407b6eb5934ab64e551279262e92edd6980095f7d6dbe1babc5ad644bf365a6f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:d9bb921e9c34bb1cc2828a6c03325ad682ca181755f9e5089d07433ca97adb6e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:cc040270cbc67fe6b7f1e82acb55e6ca55c6c53fcd5ec06e68b398a1d3bdd00c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:b1dd65a1138e1494fe76a53432bb689a36619df0899efbddfdbf16e85d2c8a11
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:d50bb732617f202a3426fdcf41267ba1c3f3321e6efc829c736f41a5422b0ab9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:4bff292cb50dc58aa5c43bcb806aeecc8479e046105d5c2fd2362ac9a93a0a49
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:90a9a929cf707d8e1a31f545a5a46c2e15e931b815c40324ee3df3302b78e24a