Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 19.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.3-debian-dev, 19.3-debian13-dev, 19.3-dev, 19.3.1-debian-dev, 19.3.1-debian13-dev, 19.3.1-dev

Index digest:

sha256:ae7c63dcafab9e6eae72860ee75c02240a83a33b273d9e8fc3f530e929ad5c40

Manifest digest:

sha256:1399e89257c99cd3334e2e61ab0125eeddbdde17a7e3008ef2113d164987649f

Size

91.04 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
11
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:ea59a7ca60651cca5fb58ea416259e8dbb0b8cbf48840198d65d10e8f54ead8b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:cbe2f0156f38736d9d2dd95ea93c433179427a9ec91bb11131d0123cccc1a47e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:7641c8772f9fec5d62bdb6c0fc360137861f12909ed32e673d27507960db2379
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:88ad9dc3dce088aa7f6a72885b61c19759dbd6156bb98e0654d2663c66df1598
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:2c00977d7798da6d4b87a9d00466da403539a072daffba59e10e8d04f0d7e5cd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:454e144ae759eaff9ce9a91d192e43de043976f28b688393099a4bf054cebcf7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:3c0a4f2eb4b9b4630c67ecc0de2b9e927193c80f6285316790ff18683ee9bc0c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:1e263dbf5d41b1031b567396e60d989fef5b73d19b9069500faaa43e585bdbec
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:420d21f217a926fe196c7ae0a889dd991ca1982fd8a4db19ab1d39a3097a6c52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:9bff80af4376bffb729f8f7fac2310c057f79679eb992787bf40cacc19d971c1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:dabb916b4084ad3835cb079a1f6096347f339ae67cce8b1561c25b96fb266fa3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:ae3815ebf7f580848b78b74edd1c5d76b611082c2b7bce9dfcb0469bf822395d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:3b583b266f80659e042b376f0152665839f036394944c9d20bd913e22f7f163a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:a28c770b61c8a57d46823616fab34e29ff066e4bc130086eea6935dc56a24a57
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:35b2521c8ba956706b8249bf83a3d3dd1c934e4ec2bfa45e535ad0e2cc42c116