Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.11-debian-fips, 18.11-debian13-fips, 18.11-fips, 18.11.4-debian-fips, 18.11.4-debian13-fips, 18.11.4-fips

Index digest:

sha256:97f29ec0fdb4ed4f87bccf2b16094faf9bc150c5d8e0d20f2724084733ce7bce

Manifest digest:

sha256:e8f3649240bb00875e22f703de5cc886196472b6b8a94a0d286faa3e921a04d2

Size

82.90 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
11
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:be6382906f73a70bb0bc7304bd59081bbf80a9ea6ce6d3ef84fa6b6826b164de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:7ca426d1c560c95801f2e16153b210f5aa2da13bd9d3140402d50d10e8f90d81
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:6f429826ac15cc144c5d34ee9388ddff6d3d5a1ef1ff47a7df9249e074929c5d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:dc09ddfb525a2c568095b5f37b012f69b2abeac9b178b0b050f8dc635020c3c5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:07b58d718159eafc3a32c8ad196675e636bd5f8570dd4248a523092f0745ae22
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:38e45b68309e6ab19335559ab8b1bb5d07593ef8f8671f3182b6c64bd80fe979
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:b9f6e36b944934cdd5a9ed58fbbb6cb60c8b3c0cc08bd8f5fec5d37fae711cc0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:f9cfbae5dabf321b4148d38e73c9038183d8a4bbea51508abb6807a5b69c39f8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:fa093b24fa90ea470ff3f7bb231920ae420e01fdf4fb653f404d3a511f1653d5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:79c9cf9306e51be21dbbac89c285310d4a9a4f97e762ec8c400b761bb421d061
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:11aa8c9f43f146f828f4fca2f4fc03a17555c94535108c5285c14c74b196a20c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:2b38dede0017afd60a6641d0dc5bf9e5e2672b08c5d57995c399b7999885f137
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:479b8157a8dd8855497011548f7530f085451c3ace63db6c053fece82744bb9c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:5b72344956c173ec23b2acd7c78b4a8f574f886248a168760dab97f1ad8c10a9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:f718452b9857bbfdfb0115f7ade62243e05c8d0ed93bb88dd1657196cbfdb6a9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:ee42783cc7df756d3e260a9d2a8f5897473b01939da8fb07192b048b0c86acb6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:eba8743a9a0545b05cc666844a499b01b1cd54cf03eb0703e8fc7ccb36e58fc0