dhi.io/gitlab-runner-helper
19-debian-fips, 19-debian13-fips, 19-fips, 19.3-debian-fips, 19.3-debian13-fips, 19.3-fips, 19.3.1-debian-fips, 19.3.1-debian13-fips, 19.3.1-fips
sha256:6989bc7dd0e6236b2cb780a3c329843ae16efe1641be3af542c2f133cc8e2d29
Manifest digest:sha256:bb285a9aed49205b4bddcc6162d52ad4d79a50aaf679897ffdd3ee1cf329c2ec
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-runner-helper:19-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-runner-helper:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-runner-helper@sha256:ade45756e4f37074bad4dbd6b7d1dd6c569538011e9a0baa37dc112165a4758e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-runner-helper@sha256:f306240897e0034cb6dda779a2476e2ecac3092669bb326ee9bc1c9340a9778c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-runner-helper@sha256:eff5029097d7bca1453a02aab39720a1d6dfcc364ad506316b0230520ad3ba46 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-runner-helper@sha256:026c293d80bd6116994166c51b357fc201f43069fe52c64f2d7c359c27beb599 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-runner-helper@sha256:2b8876a8e5126f662e0d5172e5403764fa66ce5a46734728b5717dd5eed8f28b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-runner-helper@sha256:53ef30353e902d132e4f7a4fd26636c0aa3d15b7a04b4a106b55ad243fbf18bb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-runner-helper@sha256:f207d79a2b78b3608b0170afa77a652f3c8f8853e727e642118197c1a8b4a93d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-runner-helper@sha256:b7c456499f04ab422dada0e292f6c4780756cf91700fd04302d10b9d673fcfb6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-runner-helper@sha256:c6f88e836b5b6e753e688b659217e5834febfd8ed7489ca282cdb7c6e00ee7e3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-runner-helper@sha256:097b2a9e968e74ab6fcd0c2acf5c17dfa9159a6914c7c5edbbaa876afe3d044f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-runner-helper@sha256:4bfda39f0e36bf12d7f8630d987eec17e0c9bfe3d0dd122e4f8a34d463ac0129 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-runner-helper@sha256:ea88b56370e6528e847760d9edef49195c5e1fcd292d43b21455b03d1deb37cb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-runner-helper@sha256:cdbb3e75c5cd433bfbd76510991142e3908be3906900e7bd4de76c5ce321a94a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-runner-helper@sha256:ca232dff55ecdcb8db168dbf743d1ae25db21440fe57197fff37840710c4eedc |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-runner-helper@sha256:106ccf35c451ea9cbb51412f19121ac121c475ed927b19baa34febc62bc66e7f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-runner-helper@sha256:262827d585a2c8f1187981463827e7af65417a4908a2b246f47a2a2fbe7874d4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-runner-helper@sha256:c1ace82bcc645c5ddee614d82b012517a6a40938db8302cd4357f48d44d4c880 |