dhi.io/gitlab-runner
19-debian-fips, 19-debian13-fips, 19-fips, 19.3-debian-fips, 19.3-debian13-fips, 19.3-fips, 19.3.1-debian-fips, 19.3.1-debian13-fips, 19.3.1-fips
sha256:40fcc4a4aa56a2072012eec9a173b46791ad4f53844459f066a2a80688969682
Manifest digest:sha256:d5db8faeb652e294408b1a3f124e0ef29d8fea891fb941cc0917d3f3d61b8b5f
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-runner:19-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-runner:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-runner@sha256:001694701cab62adbc2923c690d3cf42057c48ef402588fbdd1ce9f63aac235b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-runner@sha256:45812bec0adb7581b1790ff6fafc47ce0a607a752ee11a418d58e8650e1077c1 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-runner@sha256:37dd4827fd6e29bc1bfb7a44fb09392cd6fc81b5531c424faf7b6ea450f2a5c1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-runner@sha256:f04b039ff43bafeff1a119d5a9f0a8f102f1ce0c8d71ffb9bfcd2df6399636ac |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-runner@sha256:32dad1e8b68ea09658e30d563264c02d019f6006aa06c108deac3d2cf3f64b45 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-runner@sha256:e2ea426708d9a6298c4472a756b6a6acb2001f37fd836520625e9646d14ccb0c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-runner@sha256:fba395b9b60954f44ea11a6e59990a559bebfd3b18f1f7df518ace2db45d9020 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-runner@sha256:b0a15564d6eb4730ad1883886b0eae5c717c433d6200dd9cabea38d76741fff7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-runner@sha256:26f19129062e5d6203510eb80784f04224c4cc07afb6829d93403721ca1f1cd2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-runner@sha256:e68def3e3e50e2a3f88911b4d0e8988b2ef5ee5ddddfb56653e7e0aa71e0689b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-runner@sha256:6f4c0605a99d11f4f617379d01bfb7afb9f847fa4f40f4be20be55c33bd98f44 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-runner@sha256:35238dd613e26902525c23582b23ded277505b1207863c3d343c2c3fbf5e2745 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-runner@sha256:492e8a717cf19a8594f4ea1d6a72e048948a1ca9ec82c3e2a120aa8104786b61 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-runner@sha256:a0a10d37b16496957599cfc4481b6e66d333fbb77a81c122d523a3536d6db221 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-runner@sha256:649ef460a226f5eeab9c9d766e3d342c1458238a51a95cd470ed140f996077b5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-runner@sha256:c1fe4ee45998a233b677d78dd32c5bc1f0e7b0db455c03d0bbd86f5b1216e959 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-runner@sha256:b838b646dd95f8c15c9588599c9961ff6d17714c483c2f7b301b9a11d9de854a |