dhi.io/sbx-templates
shell
sha256:24586aa67e510b49ef322e879d018daf63cf986905e537a4ec5e01bcb375ab9e
Manifest digest:sha256:5e23146da9a4986474e35e10bf8bdc92c858415ffdafe943c35df4e78a52eda8
Size
385.38 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:shell2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:shell --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:0b6d1d128a18fa62059f919f0aef7ea9f56b6e80182eabe69b424afa84b05fef |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:8c9fca13424138ade6f1c02e9efdf47ab4df22a6be224d318b9bedab38fe03e7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:a7dcbc1dde2868ebfd52b157657b6d703cadfc4bebc2afdac31b29fd5b7e0b4a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:ec43ae318e08b50f9d0b178fbb81015b7f9e673d3a898fa017885e6a221e2915 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:0023f082b4324463405780899569cfde5608da6f473fa5fda5533b4480fecff8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:39ac11e725b1c7dcf08f1125106538147a6778484421d6120e66d2063ad83fa8 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:e16310c1657a9f88c3b418d9e65a7bf9232203f8a285a286e92adda1bf6eb0a4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:7ff6ae5bab26c5ee5a26385d9172187304861146b4f3f806c1616c4c0245827c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:0359f9c388cdffb0dd767e89b2df0b220f6efecf90e5273e5d7e0c41a44b79bc |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:e3af15d9d2656b651c715fe600646afe5de8c93db5ba15a287c953cda2a2e1ab |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:41f07c7080bc2dc2c4ae4ef828bf33b24dd05d4479a478857ef7bab9a27d4d0f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:8256a884560b103650752859cc3abef87eb91cb95bc676784625a13ba1fbecd9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:939b9d8d39994f4789cc84fcd5956dd1e0685d4d6080caaa0c3eef50ff9e50ea |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:78f8c95d686286ae726198835a43a37e24021abaca64eb75bf9d804566b1a86a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:5c310f3fbb12344df477fda59a95dd091bff54db6d187b314c9c16ef484eb1c9 |