dhi.io/sbx-templates
docker-agent-1-docker, docker-agent-1.141-docker, docker-agent-1.141.0-docker, docker-agent-docker
sha256:913322cb53bf1cbabd9c55112b9ef2fba5b6e06e0ef87db2312979df009f9c39
Manifest digest:sha256:7fe30058daa4589339940ae71f6dfacb25f73a059180730dfcfad26c737202d9
Size
518.34 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:docker-agent-1-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:docker-agent-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:6b246fb89c884840ee1b95b61e9fc87b5472a2b4c7470f0bbb8f6cb042f68dcb |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:324aa210c9b9594aee62802675b1d63afc2db04c22ce5c89937ae1b09b0b2026 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:e83677bd493963287f7048566b07bd63661ffba74e4b70fe528e5a0b72bb970e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:7194aa9b003b3c5b0f69a5a5cbff94848c952025c7521ff4e142b87014d553da |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:5e2859ab4eef935e1aa0b487af31564ece6768d02335203ce06e4b2c760af3bf |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:37fefda96edda9f00d159f919cab3463db03cfad3701566e5049b127cdbc2c59 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:e8166b0fe81e803c92466183379cd762c2632597e6c9ba4d87929801efa7c594 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:e8eff8264479f2e9ce8fe85ec0609b2b35ccc8e490410d33f09ec5d30bc459a7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:6c672a077f0c8650a0f1673947acf95aff8253bce910ce9b4f083d550561ab49 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:a42da5800113ad141d87a58730d274aed1d21c933de52e8de2caeda33feb62dc |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:19d52d42cb88388d2f8cf56f380bef9b1a734d69c97f32a3b06921aba13260f6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:2e36be8ce0ecf630159b80614e256907d73993f3cf20a07f1e5944bca0663145 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:6bad62e00142be77bd840d0ff5e33a96ba724bc41a15c552b1f46c82b6c604b5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:11dfd647dd0834102bde47e07352a2d77549c9e396d8a0da8d5164100ae78d96 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:2e113a0c1ecad8c13d738408b2c79e5bed61863e4bdc95ad6c8e924fda027513 |