Sign inSign up
GitLab Runner Helper

dhi.io/gitlab-runner-helper

GitLab Runner Helper 19.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.3, 19.3-debian, 19.3-debian13, 19.3.1, 19.3.1-debian, 19.3.1-debian13

Index digest:

sha256:e9c0f842891aba0b13da28c37b0d08776308f552ac0bf6c6b3679e357311e4bd

Manifest digest:

sha256:645bb89df5be5bfa97ea46100a0d6f6aa6c9e663fbd087a5819c4b58ae4f31a6

Size

53.55 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner-helper:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner-helper:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner-helper@sha256:6450db332af4ff95acb51bff805c98e3555d00cd0c8061ec4bda2d3f164fb32f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner-helper@sha256:f6ecbc6209ea0e1dc6b4c463ed6913f0ffcee1cff042018c6ccfb25917b215df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner-helper@sha256:a4561beda1267580b8a1d2933c4dba6f0d7839f8254a2410aada47c823bb8dbf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner-helper@sha256:23b3cac5cb0b2dff38b719be4258d22b8c620075f81d88ff1d4bb2e2435d7d3f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner-helper@sha256:cee86924b553302e89ddfdc53c7323c6e963d4ce1bfc92a4cdd7030462923bb6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner-helper@sha256:34ff182cbae98da8bc20c588b2280c9be5559b3a775a2343a499e62c9028b9cd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner-helper@sha256:00d4af7f1c7f422bdab2e3a290e9de5681a45b7c1ad8e10713bc749f6a2e0ee4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner-helper@sha256:6fddf9a1ce0ea3999c4a9e5c2497f935740e39232047b24eb26334048b1b4e3c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner-helper@sha256:a3ddc912e66caf0908d65edc9beaa0aed1f36df534881e53a7b1b4970b3d1a14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner-helper@sha256:f6ad9ebc2494a809e8dbc3583dbb4d23d876cac43cfe0c9dbf80426b0e1a7017
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner-helper@sha256:df54769569838123c9102ccdaf6bf799ef9d2a5ef97d62c994de8dcea7681359
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner-helper@sha256:ebba80b3077f13346fabbf599af0a4aed28da3910dc47e0bd0178c0751f1ed16
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner-helper@sha256:7d66c4177dbec7d968d355cbf370acee93afec0e8e34c44bbed8808eb4a30a63
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner-helper@sha256:bf8c4eb471faf4c4e7a54e6fb57b8a13b17660a85ef441a91f534e67c0786a07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner-helper@sha256:19d8eb19e0b6de3f244d50185228446f59691def4488ede3d8ba78954ed0cd59