Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Copilot) (dev)

CIS
linux/amd64
debian 13
Tags:

copilot, copilot-1, copilot-1.0, copilot-1.0.86

Index digest:

sha256:f0831e74100e0e5fbd1396ab935e4caa3011488bdcd994f3199b33e0e9cd3d3b

Manifest digest:

sha256:e5c3d5623a62e6e7bf8f9ceee748dd1c52a0d6ac34ab02a32ebbd37e7d58e4e4

Size

473.01 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
3
40
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:copilot

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:copilot --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:2b80bfe51a347f2ca66e689ffd5ecafee8ef46b4e1aec2e776253624919bf2b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:ce36979ef631cea22773b7a62f9bd05ab16dc19b12007eedc5d7830cf4681070
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:0b021fae766d77df2167352506d404d87e5202cfe0fa07e6bc7f101191111278
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:dd5c6fc47f01efb3a4ccf0a49342d765454453025d8c462bc990a3a21aa1e238
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:ac04cd9d641f4beb6c2bfaa2b31868aab1fda81e25731d548ade458ef9230af9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:34cc788cadf9245f95f4539a991384910bc4a04db497c8c99d8c340b16719501
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:ffea2f8d5e155948b50ec60d5b0c428b7048f09b4c36966765b4ad530510acfa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:cebf330dc3665dc41a7c7f333a16aff7e907e7d1ecbfe519c3e123ec4057fa7c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:edf8ec0895d825cb7cc36b69dea34561ca9648f33a5397ddb09516cdca767b87
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:79b1933ab5a9d25ce38704b362fa559230e02069176897573c4c6cb2f0fe351a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:8956c0bb27f5637d5700c6f418cfb8e587f66e4eb06779304dd18817de657206
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:80a32aea1b72ae8ce20b9c786bfe5b1c9358680d3a827749dd89c9df1c0d9c72
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:1f4a9e6a1858f4eefbc8f8c98c76d593c46405792c64c57899b1d8e52e6d0cfd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:ebb4849c99833b98dc8ba8d31401a4aac2ad32c204df26ac4bafc873d5616c8d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:d8d82281f03ee4d2eae93ede88c84224b38a063f358ceddacf31517a9ef944fb