Sign inSign up
GitLab Runner

dhi.io/gitlab-runner

GitLab Runner 19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips, 19-debian13-fips, 19-fips, 19.3-debian-fips, 19.3-debian13-fips, 19.3-fips, 19.3.1-debian-fips, 19.3.1-debian13-fips, 19.3.1-fips

Index digest:

sha256:0a5e76760f9b3d66ce65962c15c9a4b5ba29246a689e118fcecb17ebb391d372

Manifest digest:

sha256:e7305b2e941e440f9c705644b47a0b81fcf48b807b42b492c36845b1b7bc9cbb

Size

84.21 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
10
0

Support

Ends Jul 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitlab-runner:19-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitlab-runner:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitlab-runner@sha256:fc1afa012c680659bb70aa418ab567a5c98bb954b9765fb672e01a06ecad6daf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitlab-runner@sha256:f29e63ad96a1954fcd7e17af69bbfba37a12d478d648f99a91e868975fb5b65a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitlab-runner@sha256:80981d911f9707b4d071bb869947274e27f55e987c2c35206bc7e122e1a44c92
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitlab-runner@sha256:a054e6d2fd11a01cc1058c4b9df81dd187c90f7dffb06f29d02c98da5b83c369
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitlab-runner@sha256:fe3a85a75c6be1b6f856cf7dad4c97593b78e8ef779f6e3d28e6a560df13f511
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitlab-runner@sha256:1e3497ae0ee4c3432707ba5f5fe5ae494f005877273c841e17bb516599be2b32
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitlab-runner@sha256:55c3345ea52b805a1cd90b4424da8a458f6ba807f343e31737ef9e818e33cb7f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitlab-runner@sha256:3b97201b5a1128175c9c35141302da65bedd5e49ad72c690bc768c7d224a4149
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitlab-runner@sha256:b29a1fdf48be3d8cd626f071fae5300e2d22866a7390b007a3c680ad966fcec9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitlab-runner@sha256:4905ee4589afef571ff09f2153fe90a077dbe26544b6fab778f1c07e664f7bd4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitlab-runner@sha256:5d189cdb77275ee24d7e11f2408444369cf742903202292c0b06e8dd83dd355f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitlab-runner@sha256:69a504de9321da961686aed2df2fe4873add07615d1a57aa7509d6e280bae98f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitlab-runner@sha256:bd84f42134bc09dc373f980dade8e408acd02f7bff78f6652aa392498e0e0615
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitlab-runner@sha256:89e2e5b85e1f82155e5b0395d3b073efc5a52f7d9710a32f4bf0fff59a04219e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitlab-runner@sha256:1c04472f966b6222530d05015dfc4c8af4c12a14b498ffd7087a6b82e178b212
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitlab-runner@sha256:ea12396eb746228d57c8567634890c6ce0e4517bb6dc40e3da5d2c3c9c74bf95
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitlab-runner@sha256:bcb39b8f3dd647dba4a38c9ad52a48aea7db11938ca436a94ce438db338c2112