Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Docker Agent) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

docker-agent-1-docker, docker-agent-1.141-docker, docker-agent-1.141.0-docker, docker-agent-docker

Index digest:

sha256:913322cb53bf1cbabd9c55112b9ef2fba5b6e06e0ef87db2312979df009f9c39

Manifest digest:

sha256:7fe30058daa4589339940ae71f6dfacb25f73a059180730dfcfad26c737202d9

Size

518.34 MB

Last pushed

1 day ago

Vulnerabilities

0
2
4
41
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:docker-agent-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:docker-agent-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:6b246fb89c884840ee1b95b61e9fc87b5472a2b4c7470f0bbb8f6cb042f68dcb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:324aa210c9b9594aee62802675b1d63afc2db04c22ce5c89937ae1b09b0b2026
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:e83677bd493963287f7048566b07bd63661ffba74e4b70fe528e5a0b72bb970e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:7194aa9b003b3c5b0f69a5a5cbff94848c952025c7521ff4e142b87014d553da
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:5e2859ab4eef935e1aa0b487af31564ece6768d02335203ce06e4b2c760af3bf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:37fefda96edda9f00d159f919cab3463db03cfad3701566e5049b127cdbc2c59
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:e8166b0fe81e803c92466183379cd762c2632597e6c9ba4d87929801efa7c594
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:e8eff8264479f2e9ce8fe85ec0609b2b35ccc8e490410d33f09ec5d30bc459a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:6c672a077f0c8650a0f1673947acf95aff8253bce910ce9b4f083d550561ab49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:a42da5800113ad141d87a58730d274aed1d21c933de52e8de2caeda33feb62dc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:19d52d42cb88388d2f8cf56f380bef9b1a734d69c97f32a3b06921aba13260f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:2e36be8ce0ecf630159b80614e256907d73993f3cf20a07f1e5944bca0663145
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:6bad62e00142be77bd840d0ff5e33a96ba724bc41a15c552b1f46c82b6c604b5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:11dfd647dd0834102bde47e07352a2d77549c9e396d8a0da8d5164100ae78d96
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:2e113a0c1ecad8c13d738408b2c79e5bed61863e4bdc95ad6c8e924fda027513