dhi.io/gitlab-runner-helper
19-debian-fips, 19-debian13-fips, 19-fips, 19.4-debian-fips, 19.4-debian13-fips, 19.4-fips, 19.4.1-debian-fips, 19.4.1-debian13-fips, 19.4.1-fips
sha256:1204e44aeca8e90569d7d0814107b561753d9648eb8e97ff4c1dc0350dbbf7f5
Manifest digest:sha256:160bcab49609ee6fed9a10316e0e4e1c37234ca26a2f6f584963a8a848b94b39
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-runner-helper:19-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-runner-helper:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-runner-helper@sha256:01dfdf2bd9673dff23384a3f002141c09917b34d434af118d8c6f77e403c6c80 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-runner-helper@sha256:a1c869257810933baf3b7d51f0e3f1109cbcd858ce679c3088b46e1dc271aaec |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-runner-helper@sha256:4623f7014d8376431bf15b3669b6f0b3889a0a76f464d1a203fd0fc05cf19e65 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-runner-helper@sha256:0c44bba846f3d8c48f6eb178863ba5dd6644330a30cacc65ae00fe77f042ac40 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-runner-helper@sha256:9270725580fa6026124084f91aaeec5130bcee8f48bbf0be07b309823c324f2d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-runner-helper@sha256:b174835a5268ee2ed56a8bdbbd6ec092a214d23bd243e294fe1106973b565c6c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-runner-helper@sha256:0d1c65aab804d54539de09506797bfa829903b54c73d4268b8206d96fb737ec6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-runner-helper@sha256:4c2f498a3a165d06ce74a03b3468c83279292b4177b5330351fb8a324347da08 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-runner-helper@sha256:d583ae8af8b0329193362ccbbb0652c19e051a391a13541864286cb80b599763 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-runner-helper@sha256:d0f804acfebdc7fcb3d7cee4bc5dcf033f390d7040b7e893d0a7874c66f9d8a9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-runner-helper@sha256:1dbf73d40e59ab25826eafab68f1d8469d05fa83fa30a5e168f35a3e4529abab |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-runner-helper@sha256:4d3fa5346f7debf88035112b26efdb5050fac26efab21149a4fcbcc7d894dbc7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-runner-helper@sha256:efe69c334b28108c4cb984ca9cf8533c55c5e0900b4a030c0f223e0b00d24c33 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-runner-helper@sha256:889525ee54a64ffb385d712ccb2101e47934129b8926d0e2aeea7dc4cd453b4f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-runner-helper@sha256:708a5f1aeff217cc8ff1917b19389feee684e85d459124c95af7a4f2cd763b16 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-runner-helper@sha256:82f1b5f39e9da1d40700b2d3d01fc2ab28603e91b0e4c9e45af8f013414f2ad3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-runner-helper@sha256:3a14d6b292fe5feda732d5c2cb84d6d6c75181e0feb213b7444a918b4d63b924 |