Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Copilot) (dev)

CIS
linux/amd64
debian 13
Tags:

copilot, copilot-1, copilot-1.0, copilot-1.0.92

Index digest:

sha256:0c74924993f4a8146c0ea56832e007e6e06f8f3f40e26084cb2fe4c751c6c35a

Manifest digest:

sha256:af5cf7b6830b1a10b630b95acf59c9573f08d2f41695dfe62c6d140884e094e6

Size

485.64 MB

Last pushed

20 hours ago

Vulnerabilities

0
6
12
50
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:copilot

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:copilot --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:1d2dc41598612257bc0e1a5545a07ef05f02960c7abcaf2018e72dee7fb1feb2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:400fb20cb3cfd187ab7da55184c12ef6207abd6de8a3f39daffa6b36f1138ab6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:644f01cddda8c9c4e47690b941b8006722d95c957da2e14d6d5e1b5bd4d72099
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:91f4305803543ee8d52b2dd2b9f100124e4f5ceea692bb52f343e8a366e83d1c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:170afc514ff1f51ee179b443c3538ecc6d52ef728f31857939c126bca62eca93
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:ea14e931c9cde89b223ee4e7b1037a88c623dc9f896c6fddc9cd3bc1e8dc069f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:c6b672fd8e390e45ca14b7d879acb2f98d40ab75afdd8d418246d69435af1836
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:294527ab27e10acf2f0da97a462cd16b0d5bba57171aac30ed856191d840b81d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:bfc7eb2bdca020b5d90570070b6a56a722519f0d726409151dbf2fdc7e32b015
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:d6c7f8b6653d79ae829371dc8b80eb1b960ef41b35e6787ae7b1295dfce04659
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:2f18f5773404e8e0a93882f37ec8f6c160ccaa071e71c4d558df611c4cee5133
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:e14e65e4a2912d328c854a9615c18f3380eef1872bcfe2609594a0af5e7a50da
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:b67b3895373ffb3aa24730b4b76c055a021cb910ffc5b1bd815f331c53cccbf1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:29a923f47aa5230ae827587dbc09f3771ad78b51ee7b22fd0d92c6bdc2a72b00
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:c6a595614e4ad00c4d4a04c2222a365b93ebb39c0fee38f0107cbb3bbf954891