Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.11-debian-fips, 18.11-debian13-fips, 18.11-fips, 18.11.4-debian-fips, 18.11.4-debian13-fips, 18.11.4-fips

Index digest:

sha256:a1353f8584b243c3986143b5ea70e766a5303f334c21c0c1d483551e43d7050c

Manifest digest:

sha256:4e41a4f695927cfd90890276951328c1dc480c2d6fc4e3a4551bfe173af33526

Size

82.90 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:cd28546edcddd641fe0d0500388393d231267a35788e79b01cd18e5bdfe0c603
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:52a3e1bc9e772445983c60f5ed7c2bb2f0625ffc6476f50141e35d3f212b149a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:7e9f5d210c7a27a4dca7d7670ef62beabf281b4f0f5abd3b6602f0da8b7d009f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:7b6da342337d8dab69b8f76ab011414362c96ab5be87aa431fd95205bc8f51de
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:c06cc9e9dcba0b6079b67935d4b4cc3b3dd698ad1eb63203114ffd550492bade
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:ece8b4990610ac123abfbf9a5765e303a759434f117bf1f1252f46c1f7821c8e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:a4e8e5e870d6eb720361fb28d63f4c0eca53baa073f754e5134a7ba8b821346a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:a204b2c5deb8e1d7bd3d23f7adda8b47a5a9a879a169dade563c42eed4df2055
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:53c060b7e8e95ea36462fbadae0e65c09b768a019a81a4d40f778e80fe9bac0d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:de9e8195aefc340b74e81f7a3e104b0a4099c08b196a29708b66accd0141c1f7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:35b429d20ce17cd4c07f1e8f568731fbd7910bb2b9446c620a7c61f024fe4ba2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:f37d8a7979b15c80c388f6beb2a296bcc3c69267f43ea163a8fad869468d5d26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:ba7b85772cc1eca57e3babe56e1662d0da605d851dfc19cdd9017ca17cbed3a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:c63d88a997da83c9c4f43b69ef41ed86263a479bb98a0247e2e1674d51fecd3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:dda9fc61412da48cc2ce49185164ac8001cdd5b0f07c14e7ffd8c4bd2f7e6f0d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:52173048c5c2ddd1bb9f6c48f81c587c71b1a2b0ca361b084a133f6dec410b28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:572dc87b0605749067d625d1d3c5801c0a09aab92372c5524f63f37eabd21e4e