dhi.io/sbx-templates
copilot, copilot-1, copilot-1.0, copilot-1.0.85
sha256:16fd52193bd49bc03f55c0e8db95532dfa72cf664a627d5034d98f8d53f33dc7
Manifest digest:sha256:1345e90c77e466615b12625260d80e2304ef0c6052a6d0fc828916dc57b9c120
Size
472.44 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:copilot2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:copilot --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:f16f1c93b0786865bcb8054e0d9ddb90dd7849283c6c0dfee5e5315187980ba4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:d2c71d0f81fb10e5dbf9cee22dd382b6b3bbee84221ffb6405ffdc888c429502 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:e8177a49c8d00568af50a8ae945b6c225be5a9de6c83974466cc76a73528b33d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:3223fbfd9b1e24375375d644460e53e2ae438897e11b7e4415120167ca5911ed |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:d562f8f566352024847236e970d2888fdbff80fbddef8d1b1b3c4436786eb472 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:6b65195ea29079b29d1aa77f470e8e3b2f07eb06efedeade3ab2c69a08162bd6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:86cac83613050253d17adb34db696294d35f61adefe1ed2cfdf2df279a8401ce |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:38fbda3be9f1c3abc1d58273a42bea3f68dd48a796b79d8f481c6ee973a893aa |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:2735fccc1c74eae028996d6e6994ada43e81ae96288d70d3c46660706005dbb3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:c0613e389c946ce9122a884a5b931566c9c799e152fc9f320f0897ef363593e9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:7965d1c9022da45ebae8ea6850f0055df372af9a9f8c3fc6d18d2992fa1d190c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:be03e5138eb59fedd908c26a0b8a339e7fa9897c34e4c76718e1dbae55fff1aa |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:04b1a7f1f8a91548dc5af7897b0b7031223ee27c0399455100e22539e90ef6da |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:5e2c0e0b14cb0f342095b3accfc8423ac305f63ec6348e22b22aa13315ad094d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:580e8568b407117d5cdff941fb205d85a3e65480717f943ec5a542a557d3852a |