Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.11-debian-fips, 18.11-debian13-fips, 18.11-fips, 18.11.4-debian-fips, 18.11.4-debian13-fips, 18.11.4-fips

Index digest:

sha256:a1353f8584b243c3986143b5ea70e766a5303f334c21c0c1d483551e43d7050c

Manifest digest:

sha256:4e41a4f695927cfd90890276951328c1dc480c2d6fc4e3a4551bfe173af33526

Size

82.90 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:cd28546edcddd641fe0d0500388393d231267a35788e79b01cd18e5bdfe0c603
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:ae7fd4d327befbabc5b95847096d759d825365d5c9545c41157542be33215d12
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:7e9f5d210c7a27a4dca7d7670ef62beabf281b4f0f5abd3b6602f0da8b7d009f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:df9e23f8ab191f6c100748e20113ca3cf1da0d2dbc09411dcc91a87efb10c367
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:c5c04ef370962c035d78d6bb4ac46405b6c653ad1e1cef5f1f3712c46ee004c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:ece8b4990610ac123abfbf9a5765e303a759434f117bf1f1252f46c1f7821c8e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:560f23ce60ff2488fa0270c603987b020472220d22bc8a97b776a852783625d9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:a204b2c5deb8e1d7bd3d23f7adda8b47a5a9a879a169dade563c42eed4df2055
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:53c060b7e8e95ea36462fbadae0e65c09b768a019a81a4d40f778e80fe9bac0d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:de9e8195aefc340b74e81f7a3e104b0a4099c08b196a29708b66accd0141c1f7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:e7df29177950e038bacc04d564f32f0e8f2f06f703c8d4283b84a3d9116a8666
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:d26c626c209eb9cbd6be06efb71c7a9cbafcaf9e615cb49e93972f3605ecae33
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:ba7b85772cc1eca57e3babe56e1662d0da605d851dfc19cdd9017ca17cbed3a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:c63d88a997da83c9c4f43b69ef41ed86263a479bb98a0247e2e1674d51fecd3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:dda9fc61412da48cc2ce49185164ac8001cdd5b0f07c14e7ffd8c4bd2f7e6f0d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:52173048c5c2ddd1bb9f6c48f81c587c71b1a2b0ca361b084a133f6dec410b28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:572dc87b0605749067d625d1d3c5801c0a09aab92372c5524f63f37eabd21e4e