dhi.io/sbx-templates
droid-0.222.0-docker, droid-docker
sha256:d7bdb10208df5d7f37b4ee8c2c8546e92f2c71ae5f3f6915265720f97f00f716
Manifest digest:sha256:fa1e242861ec2715b2c7b95baaff1f8d1c9a9acbac45c586aaa470f70a636255
Size
567.49 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:droid-0.222.0-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:droid-0.222.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:f0638aeeecb1100462683ced8469a051c4c401b403d99ebda8bbc33894371df2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:2a81c1beeb8bf351241dbc818ed6286176a2abf1a23350104e07f916760860c7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:269f5e1860eec16617bee44b06894e762835e9baf85b0d20300aa4238388d44f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:feea125addde2cb9fb7954ace0d15e8d0808318a57842808144d70a74641886d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:813ea53fd0fcadf3941f1c7766cad33481bcdcaf5d1fa9ff60450ebf0311de72 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:64f814c7d105fc2a57be1b7c461d3ae2b8da9cacd5cc05a70bbfce9c8e08cc78 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:8d21b408bd4be7e731e157b211d95207fbdf6e3b3d3cfc0e49cbbb0fc0c8b41e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:ea26510022f5521c4e9af5467d2471282d47990843fdd39c90c74b09a9f5a59f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:93af3404d1738e53985fe28929b9f44dc493a2d4b10fd21d5c5f18e6cb7040ec |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:e1d2e47daa17fcdd846593a54f53320f82a0feca934be07fb5aa36b37c9ab53f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:ad767aa1d7a07e6b8c649505142a4ad6ff088d0cc443bbdcf0b1e33e1ffe3595 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:6a3e6d57331cc8767b81c4049cef82b903fbe40da7c9b02cbb5130eec804ed0a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:3a66036fd295def00faa841062bebf035a2a99bbec10851b3d4ea3712809c9b4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:6bc0db568d3fd32809d4985de1477b0ba9d3c232e93f540e8cc70d5c0f63aaf6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:7013cc36722acf0b2c1666436c3c6d33a6a1870f64713bfd25c9a17506b3d041 |