Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.11, 18.11-debian, 18.11-debian13, 18.11.4, 18.11.4-debian, 18.11.4-debian13

Index digest:

sha256:1e291f1b538fc1545f1080d0d31ff363cd9b6d6e4424dc7671ba930b63c02ccb

Manifest digest:

sha256:dc7af6f5cbc65e4e041baedd8e8abddd52b0d4cf5cdc1a8ed9aac039561d3dee

Size

80.80 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:64d7f085914da229f0c1b22ca465448fa1d6c616dcec9228f84f6818e5b9b08f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:d3ad5bc644aa43c28c7d521d409556c92ecafd17cebae35a040076e23f617923
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:7064c1d676a99f3f54a5b89989a92462d4692a46b95ca8df1494bf85bf54f147
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:9bb44be1491fe801fc0d428c7e148b2ed4c10d1d7ba5666910727688aa77d4ba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:e8935f0be2c12e5ee331ca7ee3625ce96bd0f602f2c36a6c90c71e7426ab4cf1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:eb83d9fe008ebfdc6074ac622f8ebb51608f8326821d251e09d55e9b8f03a0cc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:fd784a8c1b00303bfe10844b0c1efaccdc9e8dc774478e8de3f1e2532d4c44c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:2c196084cbaec0aafc0b59274bdb15cf6b8c7516aff64885b5bd6bbb6ceb922b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:3f893295c0f4f132dd45a30ba1dd0e363ba8e45e15a9e2259e580fb0eabb1271
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:e5c028c32cc929cf83db5a585e3c8ff68c4d4a61735a5c23df0983f48d9b3fee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:9a5d945923e5500294da334659e3f59d61da69c0e714ef93cb752d81a491f902
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:b8150babb05f5b93f7870ce79c5a44fc14ff8e0719a7e1829a6fd945c263ba75
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:0ddb9bec4601234c1e82067ca94d95ce3aa850c0b38b6d0511e27f5d67daf6a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:3659dd2d576355f92181b22775bf222a527d07623eb85e23fa86875b3ec63ff9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:7ba840f6e1d858b1535e41e1214e93276ad55dcef59a607eb92645cf3dd4643d