Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 18.x

CIS
linux/amd64
debian 13
Tags:

18, 18-debian, 18-debian13, 18.11, 18.11-debian, 18.11-debian13, 18.11.4, 18.11.4-debian, 18.11.4-debian13

Index digest:

sha256:1e291f1b538fc1545f1080d0d31ff363cd9b6d6e4424dc7671ba930b63c02ccb

Manifest digest:

sha256:dc7af6f5cbc65e4e041baedd8e8abddd52b0d4cf5cdc1a8ed9aac039561d3dee

Size

80.80 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:18

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:18 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:64d7f085914da229f0c1b22ca465448fa1d6c616dcec9228f84f6818e5b9b08f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:89721b8002e15890cb16bfd5504a3a09c20351f653a37a86b415d8f4f58c4011
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:6e48ba466a87d170c14e6eb3eda8d5e0923511beaab6f4d4712bdfd917478a0f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:ed6125f0a56d27094d033f2471cf486f368506d6e373bb0a5e592f1be10cac49
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:a8e97e7ab82c73b6f223fdcd5675449bb32e77ddb5df049cf9f1159344a0a35a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:eb83d9fe008ebfdc6074ac622f8ebb51608f8326821d251e09d55e9b8f03a0cc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:fd784a8c1b00303bfe10844b0c1efaccdc9e8dc774478e8de3f1e2532d4c44c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:2c196084cbaec0aafc0b59274bdb15cf6b8c7516aff64885b5bd6bbb6ceb922b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:ed20aab5cded1a9153c7467cb8138c1e3144e5bb39234a4a3f67ec19b466aff3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:3ae3a0ad15f88cc464ddbf24a7cb31216fca040edb78fe5e2605f051c2e292d1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:ee649fd22ec115744a0512817116bf4fd19a36ce6150354570a7e7c41a68baaa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:b8150babb05f5b93f7870ce79c5a44fc14ff8e0719a7e1829a6fd945c263ba75
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:0ddb9bec4601234c1e82067ca94d95ce3aa850c0b38b6d0511e27f5d67daf6a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:3659dd2d576355f92181b22775bf222a527d07623eb85e23fa86875b3ec63ff9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:7ba840f6e1d858b1535e41e1214e93276ad55dcef59a607eb92645cf3dd4643d