Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Kiro) (dev)

CIS
linux/amd64
debian 13
Tags:

kiro, kiro-2, kiro-2.22, kiro-2.22.0

Index digest:

sha256:ad14a9a2e6ac24c4e0f188e4e5e107ba2f205fd2dd4e22679f0e0993b63450b3

Manifest digest:

sha256:87d2430448a6f61e19a673955262886ec003961eca8c882851532802cd835b18

Size

690.82 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
3
40
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:kiro

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:kiro --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:4bbf924f48c6ec61bb294e74eff6cd2f924ffa18bec95119cc69fee5c05ec9c9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:24c51d9e25b46c2c0b296ea5299726f31b7bcb6d2c7b5dd320780ff2d57b7675
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:d7005f3e321f4b60137effdcb8fdb288a1561d9b29bc44b07a895aa8edfc745a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:af682ade702ee4df87d0cfeec91928071bd235e61c37a0c7414b476ebb87304b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:888ca6a54bdfe48fdff648c883ef08e6b6cfb5fcc7018dc6c1ab89a96fe037e3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:4d6e1c9f28d6aea6034e76dd9392ac67cb972449076e678654e4efe66f89b543
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:ec4afa978f141e54bd171eb319cc8bf6c61817538f85b2009c6a23ea53f90d54
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:58a173deeb7f6b8cabd99f34cb3e72227c9d33b9cb5fc56d10c5a17979ef59c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:18c357fe63882e95ef04d832bebc2a76df8232039f034adf243e85624b1952c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:a62e4888993b93adc655f340356f522d164e72c01250d6a822b1ed750dd04916
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:2d1337966aed57d0e9d0cf107fe4c43b6877ce9dbe89c35ea4e4b823a2a0f796
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:f730f81035a79c7b4989e77eea6e6ccd4af9228c53b19645b2de3ca2c07524ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:dd128e9f55b1834e87fdbf820abd2e5e383533a434e38c2562093ac05ee714d4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:536cbd4b7bbbdc1039db11320e510e4e7d5293a79119495645841329b366eb46
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:e8daa1fc3ef6c424485af29223ad9ede63e94d6706841d9ba6ea0cd9f6b2fea7