Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (dev)

CIS
linux/amd64
debian 13
Tags:

droid, droid-0.219.0

Index digest:

sha256:ac70bf73eda3b506921bf804347f81d2bcc412b004bfba1585793d82eb5d921f

Manifest digest:

sha256:fae3fbefa2e88d51db71458ec2a10cb708614b84232a189a046df977b7939987

Size

466.02 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
1
40
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:bd11cc996e38dee3459b3c86b07deb8185f312b0a4739b9b781deb7b4041752d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:3a9d43602103fad48a79471feb294595f7dbe279072c67928bf2f0ce7130041a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:c5afc9b12c26297d5edfb41460839890c0dd01c6e99c06a19d0d2889f59b792f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:67246cf0003499c6b87ebdc7b24cdc8e857df7879baf704af628275b15dbf283
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:2e6dadb1337d901739a6f8a3e0a192dd0b00380a03e1cb6056b680ea42a9b623
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:ea40dcc95eda825b7b948c2960018526d93cd324ca208bb722c594bfcfeec68b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:7c3cf0770e63cdb63aca9ed7098f1227d77096c389ff8367026eb13e9b491270
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:4c25fdc5a838d44d77abc868ee18e2561eb4653231bd649283bdeae09541e65e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:93f5eae0cd35d8db580fc1aa980ffa5416410891a9a14996ccb5df47a2101ebd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:abeb02d04fb64bb7d70e4c8ef6ede06700a88047e4b8ae0c4e662228af2f0579
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:95d1a45b15430ead2aa60a35f67c3e6d62a474e40670cb6bfb52873c1df95b5d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:225e02626fd72d110067bee92d62a4fc5193b913631d729ec26c5d3c2bfd9ecb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:8b0f58eb8d5cfceb92bce9f3b67ef71c1d51e7084024fc260dd10fa94fb3cced
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:8e530354107e9f98ede21cdc0e751f0d0fca0a6cc06b17fd11964e093c697ea1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:7b9f7b4a3b2e9ed489da53d75ad2e83cd7d22ff8222ef625917e3aeedda24145