Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Copilot) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

copilot-1-docker, copilot-1.0-docker, copilot-1.0.86-docker, copilot-docker

Index digest:

sha256:077e1c12319ad9bed85cf0a70e72ce27675913ff9799a2dde3b3bc027a716ad0

Manifest digest:

sha256:fd02817c6fcb242864be770b63ac5b18ae3c216ff290271276ee3ee2d41d0c24

Size

574.14 MB

Last pushed

54 minutes ago

Vulnerabilities

0
1
5
40
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:copilot-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:copilot-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:8ddebdb0553648f13d8bdfb00778b2766c2999deb2010b36d2b9cd7b6cb87caa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:9edc48522927bf8f88be635fc3562c5c0505aba13d29c8cba1787417d16bf2be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:cc5c0b2b88f869e22a9be19e1c015cde9a7ea1c8c4005b6b46307e3f42d27277
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:e665e0043b6f75fed5db1a6de24487c8fc22b80347501a952e531c5ba8371469
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:9a198c2c52d1f24e32b4fcf3f2414b1b735be1877e0297f0f9d3045f4f6308e0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:73fe6d9734033faa9b7a3ee4c6437edade95e9f5447ec2b32d205408a7294c78
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:0ec67ac0c8b687a8001d7bf7090b72c4e0fc8e485472b839c8e3c5b7662c3284
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:38e66a8e9d6623ad9ce6e473099a67ece559f6db87e58237c6103d40c80f97b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:ae4f8f3bc29de710187fb5fbfd674b7da9b1912c47e2b0a0f5a7ea36db19729d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:935aab6ec0e7ae18fe8cf301c35265be8193b17894a48ddd8d6366291538c492
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:981d45aa21062bdcf5319456e2d5acd26450d98ff2cf77d363d295a89dbbd9d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:bea78d3e673ce6ceea49d56c4af89261ab41d33e72e8e56a695276b23ac442dc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:a676bd3bc4d4a32d2ccd4e04cf370d6acde9dbb5367d6906d2e65106687d1641
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:936c60d1f2e5aa8bad27eff678eb5a3109a2b0b544cf9f2809770e8828181b00
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:34abaa10d134dd89b35972f654a133e6485042580edced8b8a08d22bf8c8e150