Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

droid-0.222.0-docker, droid-docker

Index digest:

sha256:d7bdb10208df5d7f37b4ee8c2c8546e92f2c71ae5f3f6915265720f97f00f716

Manifest digest:

sha256:fa1e242861ec2715b2c7b95baaff1f8d1c9a9acbac45c586aaa470f70a636255

Size

567.49 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
6
41
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid-0.222.0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid-0.222.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:f0638aeeecb1100462683ced8469a051c4c401b403d99ebda8bbc33894371df2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:2a81c1beeb8bf351241dbc818ed6286176a2abf1a23350104e07f916760860c7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:269f5e1860eec16617bee44b06894e762835e9baf85b0d20300aa4238388d44f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:feea125addde2cb9fb7954ace0d15e8d0808318a57842808144d70a74641886d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:813ea53fd0fcadf3941f1c7766cad33481bcdcaf5d1fa9ff60450ebf0311de72
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:64f814c7d105fc2a57be1b7c461d3ae2b8da9cacd5cc05a70bbfce9c8e08cc78
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:8d21b408bd4be7e731e157b211d95207fbdf6e3b3d3cfc0e49cbbb0fc0c8b41e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:ea26510022f5521c4e9af5467d2471282d47990843fdd39c90c74b09a9f5a59f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:93af3404d1738e53985fe28929b9f44dc493a2d4b10fd21d5c5f18e6cb7040ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:e1d2e47daa17fcdd846593a54f53320f82a0feca934be07fb5aa36b37c9ab53f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:ad767aa1d7a07e6b8c649505142a4ad6ff088d0cc443bbdcf0b1e33e1ffe3595
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:6a3e6d57331cc8767b81c4049cef82b903fbe40da7c9b02cbb5130eec804ed0a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:3a66036fd295def00faa841062bebf035a2a99bbec10851b3d4ea3712809c9b4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:6bc0db568d3fd32809d4985de1477b0ba9d3c232e93f540e8cc70d5c0f63aaf6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:7013cc36722acf0b2c1666436c3c6d33a6a1870f64713bfd25c9a17506b3d041