dhi.io/gitlab-runner
18-debian-fips, 18-debian13-fips, 18-fips, 18.11-debian-fips, 18.11-debian13-fips, 18.11-fips, 18.11.4-debian-fips, 18.11.4-debian13-fips, 18.11.4-fips
sha256:97f29ec0fdb4ed4f87bccf2b16094faf9bc150c5d8e0d20f2724084733ce7bce
Manifest digest:sha256:e8f3649240bb00875e22f703de5cc886196472b6b8a94a0d286faa3e921a04d2
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-runner:18-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-runner:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-runner@sha256:be6382906f73a70bb0bc7304bd59081bbf80a9ea6ce6d3ef84fa6b6826b164de |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-runner@sha256:7ca426d1c560c95801f2e16153b210f5aa2da13bd9d3140402d50d10e8f90d81 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-runner@sha256:6f429826ac15cc144c5d34ee9388ddff6d3d5a1ef1ff47a7df9249e074929c5d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-runner@sha256:dc09ddfb525a2c568095b5f37b012f69b2abeac9b178b0b050f8dc635020c3c5 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-runner@sha256:07b58d718159eafc3a32c8ad196675e636bd5f8570dd4248a523092f0745ae22 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-runner@sha256:38e45b68309e6ab19335559ab8b1bb5d07593ef8f8671f3182b6c64bd80fe979 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-runner@sha256:b9f6e36b944934cdd5a9ed58fbbb6cb60c8b3c0cc08bd8f5fec5d37fae711cc0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-runner@sha256:f9cfbae5dabf321b4148d38e73c9038183d8a4bbea51508abb6807a5b69c39f8 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-runner@sha256:fa093b24fa90ea470ff3f7bb231920ae420e01fdf4fb653f404d3a511f1653d5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-runner@sha256:79c9cf9306e51be21dbbac89c285310d4a9a4f97e762ec8c400b761bb421d061 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-runner@sha256:11aa8c9f43f146f828f4fca2f4fc03a17555c94535108c5285c14c74b196a20c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-runner@sha256:2b38dede0017afd60a6641d0dc5bf9e5e2672b08c5d57995c399b7999885f137 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-runner@sha256:479b8157a8dd8855497011548f7530f085451c3ace63db6c053fece82744bb9c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-runner@sha256:5b72344956c173ec23b2acd7c78b4a8f574f886248a168760dab97f1ad8c10a9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-runner@sha256:f718452b9857bbfdfb0115f7ade62243e05c8d0ed93bb88dd1657196cbfdb6a9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-runner@sha256:ee42783cc7df756d3e260a9d2a8f5897473b01939da8fb07192b048b0c86acb6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-runner@sha256:eba8743a9a0545b05cc666844a499b01b1cd54cf03eb0703e8fc7ccb36e58fc0 |