Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Kiro) (dev)

CIS
linux/amd64
debian 13
Tags:

kiro, kiro-2, kiro-2.22, kiro-2.22.1

Index digest:

sha256:3628496b5e8a6c2db8579b7531d44889fd0f56658ca77ec2e3f8264834b157f5

Manifest digest:

sha256:b0956d09f7f8d5ff01fc3732e9350a836a370c78aa7437ded4190a7eb2dfdddc

Size

684.29 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
1
40
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:kiro

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:kiro --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:f029aed597a736cae1c6ccb35402a0a8d1cf5392937383a816e2e0d4e0f1dc2b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:898e13363df87797d53df8668873f32cae847eb437400e0747787fbac878a12a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:f70a32b706f1fafd7a8db576bc2428b20417ee77a60436fcee242b1d61e28fac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:757faa26e6114c93a88066a63985f1de100348ad125b4c800a162ab1e699e2ea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:b6843583bf863b00b6ecf3f3b4da681e14f20cd0cf857cbc284aab1660708401
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:8a2f3b719341e5f4c52dc52a53f7cb6a3bd21ee74d6c3b73ad2999f744a4e14c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:ecde73d8a67e5f30c32901cf2ae5bb2afcfc69d1dabfc24df47f0d41ec516da6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:520943ae1bb6305a4b2236c85b049d69bc7b2014ac1cb612f78b397dfa3d53e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:deb7f036223d769bc3b2a0ad79d8ab08fa937ab2e743baf079048cb6639e05bf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:5568cb724e3e21dd3e1608c279e53375e0996e12277b8be6e6f06274ba306f7e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:3ad24518926127574c196bcbe4932d48ee3060324be65f185b09e90d9a7428e0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:5d32539fc4e19fdd050b24558faa1d4dfdce076f8e559b4a1b062d58b7470fae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:d7c97ba82ac8d12cd72cdf0033577b4da0327b37affed1e1ee4eda96bb07025a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:2e35754564d1ba6aef20f4cfb6efb8556e855c4d096e439b6751a9f19ae87dea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:862a767d0b23c09f63de0ef70791704bb88fb6b8d2d7800dbebb598fa25bd708