Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (dev)

CIS
linux/amd64
debian 13
Tags:

droid, droid-0.223.0

Index digest:

sha256:1ff6c6abcb06088ae5ea93f4fe546588ab85815e3119033e90f67767d19ffbd4

Manifest digest:

sha256:6ee84a9851c4e8d44ba9c1f36f34c693bb3ea9e0ef0b925a4b0a3c6ed30c7ac5

Size

482.42 MB

Last pushed

1 day ago

Vulnerabilities

0
2
1
40
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:a1024887c977fe4c2dc4d797694ccaaf6d1d842682fb1e98abf8e1c6af15353b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:200e07a87e112ce3199d5d07e6b2a6bde204a4cd88dc558527921380bf234580
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:4cce70796655f28b1d3d584d3135b33cadc406c5648593679c8103c9fce3ce17
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:e8b56aef3d82df600ce45b817221e2134ac7717b97eb86a845143835231ed53b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:08d1aa6c06b65199a4c9c6741e138ef87f3d29c07be203694e5f4c2bd670478e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:9e517d0c53b2dd6c4a3afda796338fdbef800cd8bec0221d03cc9265789c26b5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:2cbd7574479d839e3405b18d1599b93a1f97ec71d82f28d5dc61e191fc2da5bc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:baad04e4690134be1b7e1d6623cf4bdf0a75ce8776de8010672f76e6c0c202f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:be5031e969eb7007cf28608b5a978781f8d7e86fe28bb649695932d2fb0ad9fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:a50747a799745a5a39cc87e3b37c7d466613c58ed0003eb9d9cfb14d77d2dd04
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:74146f90b19502b5861d675c422deb0fe695a2c97e3d9c8fce3a08a39ab02c71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:5f556cc09171ccbb1056e161d0310059f65691eb8816733b88675ad6ac1614a5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:177f75fa829e2961d3665a8ccbb4ee6835e851d513f21daf9769d34b727c7a86
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:70f3edc1b3e5abd50fa5769805f90f5412cb3f5bfb35dbc67a6c27df358d71b1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:3693cc8fe5990ac0b93072fa9ecfa948f54b85f199b860f8894b63a572525ec3