Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

18-debian-fips, 18-debian13-fips, 18-fips, 18.11-debian-fips, 18.11-debian13-fips, 18.11-fips, 18.11.4-debian-fips, 18.11.4-debian13-fips, 18.11.4-fips

Index digest:

sha256:9886c78859a35fd481501f675c1fee6bdfc0411a6e261d7d03726a5c0b5dc5ca

Manifest digest:

sha256:5299a6742f57e6bd5e2a7e7888be43091c0f9e948434afd1844058ee79617c00

Size

83.23 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:19378f2f0a3d96afc6e147e994bac80bed40797f8452a09e5da891da7bcb0e43
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:9fe90622090980ebc128f0a212ce6c6c1445e45b5b5498462ae64d8d563466c7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:f5818fc92ad625dca2e95b7d8b6c0941b55c89effb4f33c6e4e323c2335045e5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:9fdf118ce5d9f3f0695dab2fc7c0da43212513928780db647758df4eb262bc3b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:99b85831ef5cf8840fdf11dbec9b12f401e19485cca124af5284d17486e7f8d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:663fc14adc65ec457da497582598047ec2dd13fc8ca60f5b2e8f635f0af46c64
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:4950bb62602575f8ceb678cf921d173d1464b52d71d2152704c209b5643d52b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:9031d8c95e3a0245b9f5dbd2355857d2794997f9036290ce0e0bffdbab36fea1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:06b362e6ecc8b6a3e07296efb16ebb14ea8dc04a38d110753a94bedaac98af3a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:7291fbe9b5dc34246ffa30466e3eb83e94e0877895035f0d4eba44047b731b44
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:450ffac3cc4c5c99f61dc045c5b776a777bdc3ffc36fdf785c6c64194fbd4a51
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:1164cd017d22837a0032531880063f0170be988c87a00b94d2eb858daaedfcd0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:13ddd9b04049b04bf9f3752d31fd60c147575b982a7baf9ad83e566f0fb1f0bd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:0ef4fe5e202b0c2d009d86b4f78f2c925675fc6a2959407dfca0067688f82ce8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:7f0d991eee81d118ce63e03cf4266bea476eba58ba8f7495c4e319417181111f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:5c1b4a7408ef88be5d80d1248e27493f141adaa2f3d39b25f552fc323e29fe22
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:17d013f1a286fcfd0eb62cba36752c63830b371db726eaa605a03ad06fecf2c5