Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips, 19-debian13-fips, 19-fips, 19.3-debian-fips, 19.3-debian13-fips, 19.3-fips, 19.3.1-debian-fips, 19.3.1-debian13-fips, 19.3.1-fips

Index digest:

sha256:0439a341b9b920a15942ae5bd5da4a33e4df22f7232a5fbef66323d1bc9a9c19

Manifest digest:

sha256:4e342a30d9c38b4f8f84f1721370993750e2da5615dc6d4f5c06f8a93d7e94d8

Size

83.93 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:19-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:3b93653429a88a246e32f22407740b228fac27a7a40034f947f150811c8075a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:3d1fe461013567e9dab5a52becf0fb9e6b911948c52d98354d50c6c3d7d5eda8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:a540dcf26f6aa53300c033daa37629680c5c9903a737dc5d30bb393dde7ccc4f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:8011e023394cfee4014250ecbc9b7b3ac68b535d31139f66761a4b8aa4ba8aa8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:59e26e43f2041a855f91c34f6b47d3faabba12d96f295a1a56d29f2743e1ed9c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:ffbb29216e277eaf6b7c30f64ec0d6153a6605891bf62ee844b94e9a510075de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:b510d8391e0b78d2aa98c2521372811c39a0322389e9b58be871472ae7cb33a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:ca9001b8967cee4a35080117e7e820fb95570499c7368f91823686f2fffaa1d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:5cd83bb73d99ed000d2392b16d72ad3dc8e0bb616965266222914ff75f47c083
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:15e4e93dd0c10c6a7463f83a388ea37826252719883f3b5bfcbc5890834456e8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:ece870f973f5000925dce07a1b7a105c44c88310c711a067928532fb34121161
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:f2a77e60ca76aaab992179f62ead26bc6b98fd1b56bb3e2d310257077594b782
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:d6452163245572be2451f45548b7be2a21a5b160874ccf657bc4394937bb5312
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:cff78a2763f42972ad66e5ba4801626d45f3a94ec66ca4da51373577beea42f9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:26288e3c4496c75c2067361e21a1a05c874ed91a7301a0bd6cf5e48cdb08e6d1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:e5be0c32be711703743122fec24b521369e553bf91b95e5abb34f47b48dac967
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:a9c0d4e5b4b36bb6473a0ded7643b31824a236d407054fdf7b902b271c8f9e99