Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

droid-0.224.1-docker, droid-docker

Index digest:

sha256:87c3c289a4389bc2d418bb3cedc6ecda3a6546dec5ffec2405847bc35f6b2df7

Manifest digest:

sha256:9e2a88a627f17009fa40fa128aae6d24aece209c163cc57eebca735c2d38205a

Size

583.82 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
4
40
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid-0.224.1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid-0.224.1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:b93430860a88b62b81e2ce693a3fc933cebec12e00f187f37da31a7aedc1810f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:80f619efe3695071798506d145cedffc04bb7cedebb2786e21892d39d0b983d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:08c6b5ed5531945f7afe4ea7681a2231c986db06a611e3d4b81dd3889488b37a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:1db2826d0cfc3f6964958979f4c76d6b670d2e3560a7d957ae92dd81ef71d65a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:caa823cc84ad09570ede6aa9511eb8256acad8aebcf1e25c6ccc36c3f9d7de24
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:6a071f5203016d3aae1e8469727dcb274fe8b9b9d43bf629739f3dafc4c62ff4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:170c97f11ba591e642c97651cba6632118f0c0bfccba6bbc5e8f8bfed6c80430
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:45434e79b591fbba4a48025cd5c36648f9e3a90db766fba8cbc6cc898742e22b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:5fd217a8029b76df9b9a398c94e678c94de725eccac7f90741820829150702b4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:466bf5d97c686307922763ea61269a029b07529283209e6e65b360a3c4740038
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:8f9ef609c7708c6a861a2056069244041728f0bc7bbb920f70cc7a1715e079c4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:ba26e24f047f68a47f01ff5bfc22987358eb86a095522ccd107d841237e052ab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:6c008e411f3b811d479ae6d38c17e8ceb09f8b4dec9be4568b9c751457e69b3b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:1e308b4a66523c4b740d25926c6890f02b94581324a0aa7e3a1d5c28cb6025bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:9b4d3094df80a012dfb5396b8b969aeb1d816b8a06c9e07291d814b5f328e8f5