dhi.io/gitlab-runner
19-debian-fips, 19-debian13-fips, 19-fips, 19.3-debian-fips, 19.3-debian13-fips, 19.3-fips, 19.3.1-debian-fips, 19.3.1-debian13-fips, 19.3.1-fips
sha256:cc13d832083e94d1f4d566309edb6ff2c5491a27a43abc078b6bc9a8690a5ccd
Manifest digest:sha256:bfcdaee891db154ad251ec82a99683575a8416fc02dc326a3f9e2bddcda10cde
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-runner:19-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-runner:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-runner@sha256:0a0678d4316af7d89bc60cfe11fca320af15f966ac533df7aeeb7af9f6dde4c0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-runner@sha256:d24e3040bb8e1d01deaf8325eec89ca7cf9e86541b7bb2451d39cc78747de688 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-runner@sha256:c932bd50f6478686de50214f028ef415728a54c7d4ebc1b755c55bbb9e4aa7a8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-runner@sha256:f72a88a9a0fa328505fb1b405975357be00da3c112bdf38c41b611c33065af0f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-runner@sha256:dd27874ed605055561073db1f0ea6563e96f14117992f1e0af7b4c9e794fb00f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-runner@sha256:d24ddf17c1dfa6b03306c942e4317e20304893636806ae8c7bab1be0c4e1a117 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-runner@sha256:198beef7083f8dd8fda4e257b5c1b80b20a898c13630dacb3af73143386e44e2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-runner@sha256:b8d9b70b466722dd2a2b50b13da68c0928203b862e472e6069fe66a8d6d6a2e6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-runner@sha256:6bd991b9706f5e1f1826998677051355ffebac8e2797daf1e538ed3d73dd1f1b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-runner@sha256:1e91d382a2a468f4f6425106ce44c8443397eb9db2dea26257d1f7cb49a8c58e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-runner@sha256:5b910a397a8d2ea9c6bf390b1e1e92fe0e309412ac8d6807633b0dae07ffef69 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-runner@sha256:d25264574a3231f19cb1f0e3b39538ebf7c05b1a063180fddaf150f94b2a1f40 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-runner@sha256:5491ab62ee53cf56f21b403fa96e6aa8cfc8cf5235810ccc9643f2cee4751d4e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-runner@sha256:42a9e82a7db4c02a1cf06e856a22114c51756e8b3ad566d44347b7c53b6c0991 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-runner@sha256:2fa607c4fece43a570f42d923698f4f66b6eba070571cf8813431f0b37a0f860 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-runner@sha256:fc6fc3e5653db27eba025a0d824002f8970911a652452212d849ce0604cea6f6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-runner@sha256:e6266d37f0db1f4cd0d09b73fc2b9b2e2a05c02a41baf213cf7c4e7863692928 |