dhi.io/actions-runner
2-debian-fips, 2-debian13-fips, 2-fips, 2.337-debian-fips, 2.337-debian13-fips, 2.337-fips, 2.337.0-debian-fips, 2.337.0-debian13-fips, 2.337.0-fips
sha256:7e62c8640d28627b93e87bb2b6b3a3e6a8502807e6d1311dff43c5a68bf27233
Manifest digest:sha256:1babf07eeeef31c542b2b6b0d826835a53b1e4826c6c2464f4456021575a81ac
Size
252.12 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/actions-runner:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/actions-runner:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/actions-runner@sha256:bcb284b2ff1be409f7bd371e49ead63b5472a7f2c04cd2be66d6e563d47f430f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/actions-runner@sha256:e3206c9210901799cd71bae1d5cc6440de96f98247b65c5b60ebd3afe696a204 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/actions-runner@sha256:9cc0c3e8141c0fcfe2abe430f744213e35c16d9816603339864a2267e233f639 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/actions-runner@sha256:a9ed8716e91470e9c8b455d4a551ac743e612059c187da78f1c1ccb28903d830 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/actions-runner@sha256:701240338bcd6bffa6fc2fc1850cefabb1412a7f31a22cfa77e85d6e439c69f6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/actions-runner@sha256:90410ce1d29423c4c95a1317f189312b8b777f99034c72ca646dc8bb3a42aa77 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/actions-runner@sha256:81a872cb863acaf6d85a6a64255686aee16a5a111bf3af3ef9d657ab89dad329 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/actions-runner@sha256:a1c079e55f4ced3b538748d46e47d5dc81788715414a0674d7c9b97a13a0641d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/actions-runner@sha256:a716eb7b3bac7c3cb2b205d5617433d4959070e48c09f4c96f9a63d2c1e7bcc2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/actions-runner@sha256:cc587d2b8f6b2f282ac99057ed511f29934172233e59f488be5ed06d7a8a1e9f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/actions-runner@sha256:660b2b6b26b1cddd255b01243b021f83521635ab729edd197ea90cc211ae9111 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/actions-runner@sha256:d31cf35f64e4ce00bff77f882d038b48571dc6de32c362b3de13999b429ac04b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/actions-runner@sha256:6eb7ad21c76fc80c0ac4d7dc6a59d42073536e912655802e72453ff18704ba55 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/actions-runner@sha256:ca827f9c7310126f6b5fee57cf62bfb61eb5f5e723042a3a156965d3ffc231ee |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/actions-runner@sha256:fb2a0567f0140eea03cea80bef2837a7721e042a91b8d1b4a9c577872f9bd706 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/actions-runner@sha256:b4d23cc16fc7f5d9f98210b0b454427d9f19976642cbac42eb2f93f606d9111e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/actions-runner@sha256:1fbdbe171cda28f5feb713565c47685e04419bc57d82fa7ae25361cd69a5b029 |