dhi.io/gitlab-runner
19-debian-fips, 19-debian13-fips, 19-fips, 19.3-debian-fips, 19.3-debian13-fips, 19.3-fips, 19.3.1-debian-fips, 19.3.1-debian13-fips, 19.3.1-fips
sha256:0a5e76760f9b3d66ce65962c15c9a4b5ba29246a689e118fcecb17ebb391d372
Manifest digest:sha256:e7305b2e941e440f9c705644b47a0b81fcf48b807b42b492c36845b1b7bc9cbb
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitlab-runner:19-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitlab-runner:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitlab-runner@sha256:fc1afa012c680659bb70aa418ab567a5c98bb954b9765fb672e01a06ecad6daf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitlab-runner@sha256:f29e63ad96a1954fcd7e17af69bbfba37a12d478d648f99a91e868975fb5b65a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/gitlab-runner@sha256:80981d911f9707b4d071bb869947274e27f55e987c2c35206bc7e122e1a44c92 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitlab-runner@sha256:a054e6d2fd11a01cc1058c4b9df81dd187c90f7dffb06f29d02c98da5b83c369 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/gitlab-runner@sha256:fe3a85a75c6be1b6f856cf7dad4c97593b78e8ef779f6e3d28e6a560df13f511 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitlab-runner@sha256:1e3497ae0ee4c3432707ba5f5fe5ae494f005877273c841e17bb516599be2b32 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitlab-runner@sha256:55c3345ea52b805a1cd90b4424da8a458f6ba807f343e31737ef9e818e33cb7f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitlab-runner@sha256:3b97201b5a1128175c9c35141302da65bedd5e49ad72c690bc768c7d224a4149 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitlab-runner@sha256:b29a1fdf48be3d8cd626f071fae5300e2d22866a7390b007a3c680ad966fcec9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitlab-runner@sha256:4905ee4589afef571ff09f2153fe90a077dbe26544b6fab778f1c07e664f7bd4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitlab-runner@sha256:5d189cdb77275ee24d7e11f2408444369cf742903202292c0b06e8dd83dd355f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitlab-runner@sha256:69a504de9321da961686aed2df2fe4873add07615d1a57aa7509d6e280bae98f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitlab-runner@sha256:bd84f42134bc09dc373f980dade8e408acd02f7bff78f6652aa392498e0e0615 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitlab-runner@sha256:89e2e5b85e1f82155e5b0395d3b073efc5a52f7d9710a32f4bf0fff59a04219e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitlab-runner@sha256:1c04472f966b6222530d05015dfc4c8af4c12a14b498ffd7087a6b82e178b212 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/gitlab-runner@sha256:ea12396eb746228d57c8567634890c6ce0e4517bb6dc40e3da5d2c3c9c74bf95 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitlab-runner@sha256:bcb39b8f3dd647dba4a38c9ad52a48aea7db11938ca436a94ce438db338c2112 |