Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.11-debian-fips, 18.11-debian13-fips, 18.11-fips, 18.11.4-debian-fips, 18.11.4-debian13-fips, 18.11.4-fips

Index digest:

sha256:280caf829bcf3e9798870bf332a2926f60f302d922af4c068ce2644d1fbcd53e

Manifest digest:

sha256:f8c730dae3ce5bfc29cd78d220da50e1116930b0ba59586a07810da620a411e1

Size

83.23 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:883110a274e6307938bbc9ffd14ff20ccf2a41fa4780104881a8747d507c2ae7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:a6f93f86b4b713004242887a41f516619bb804d1fc40f8c9c42a8ddc36014258
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:449540f5cfd1668b77f0dc0e1782bc9ab41e25f1ca34c769f81b634da94b0d2f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:9d942f4d31ccfdaec4ca25df80d35415434a5d7caa1ecb46ce72e72110c02af2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:2a2fed178a09d6466c2219715f52cccccbb83ca7ded0fd332a314da429f7d523
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:cc54546565ef92df074dcdcead310a23e856c2a91e7d1965e6f7cc57c22a5f2f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:8be5386e71a9d0b43a3b5c1a92b864b6a10148b369f104522234d7f0231b3088
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:545f30c831a59680308dbe9a84d4b7e03e03ebe261ceace06c961c7a19c279cc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:ac72bc878d88393300581d332c3472fd6d512c4e8ec0847f10640ae2f2b2abdf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:2235271e4ea1f8e4743cc31954ee1fde56de41b2f58fe1aca35bdc49222db30b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:1c69db18802f23832fa889e2cbb2b23f4023594504338112fcb602e79556e9cf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:04249220c1f5d85ca563786db8177d40348c09359f4b9177fb010c78dc8cbd9d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:c99d91b3630def8135c46e40a54aa18938429cebc28512d51ed9e363743d89d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:ac4c9746a6e166096c9a5f46c2422126d901b34dd50c0d903edb4b8a8d4559a2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:13992ae1253cb199c40b01ccb9a98ea171f0a85eb1663e3c3b6ca67cfb70d935
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:a9f7e6ca0463b7ec7036f99795633d6010b9f5c2bd7229c8e438783f3456dfd0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:35f4aa6329c9f0792beace3498d670abee688baae6e40a64cfe0b1e46f223e12