Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

droid-0.223.0-docker, droid-docker

Index digest:

sha256:a63dd284908a7c8dce4aef548991b96a7519596345541dfd58f4b44588c2ff1e

Manifest digest:

sha256:3af2237abe9924093df743b88efa8e8c322ad9760ed426a9123b56cf69703cd7

Size

583.46 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
4
40
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid-0.223.0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid-0.223.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:bb3ceda1ff39910568288b2fb91ce7394dc2d9cc6598b0485d170f475ff6e132
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:c2765c67121971c40c7bb26495994eb21401d66a4fffe80f76456dd02b156397
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:e020a0fbfac3620b0d426d263b87ce3328328f9b131789ac27d1b63b134f194f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:fcad7237b3c281d5f69bdf2e02e9e46fbf62f7d0e3bd69386367bf0c3b2e58ab
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:fff53c0bca59da2ea4d2af99f5077ade245ed887af5bb88fdafafbf3596a2efe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:f334d6c146891a6b302ac0f80cdf6818b1779af495194414cd6ac7039ccd6ad3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:0353f304b09cb7a0f47c696e0562dcfb7b8cbf4c64d18b02ca6e4bd5c44c225e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:a031ab4b1ebcabd8d7162fcf87c89599ee9a968dc5c9db6a15d0f19f2c6ee52f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:21693797712f581093fbb7011733f40f7b2ddc8a665f0198a9a117e3c3c5a174
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:6cd4c4e7b99271356898b16372511bb2304b4b5d1d3cc7025fe39821ff330cc9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:b6c8bcf2f603ee94ad9aff2e22fb1b228e4166b733d5b5f53d45a3b4d512bab0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:b57ecfd59d0fc7268a08d4651e85d3494b255b77771551e19490a86865555b2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:fd19091088f489ea5e7f355d4d97a1b09fd9e00e860640c64b3478e00d31c065
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:c47919f8d31116961896dfbc61e337cfd6edc5dcc98d00c5227c440f64663f15
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:f54485f9bf6ef09502d20c6af7623908e96cf695ad8e3044075b8ca3f3ba289b