Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Copilot) (dev)

CIS
linux/amd64
debian 13
Tags:

copilot, copilot-1, copilot-1.0, copilot-1.0.93

Index digest:

sha256:089d197b7b6880874edfcdd6d53202a766699aa4c11ce2fd7c7280c6de899e65

Manifest digest:

sha256:fea20d58edfc81c95bc57336b0afd0a7dc9c9e8f3bb88effee83f40c8d3b0d4e

Size

484.89 MB

Last pushed

3 hours ago

Vulnerabilities

4
18
10
44
8

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:copilot

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:copilot --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:16211183e6d35537fbeefa8ef05497e14875d47cde2018dc29912daec981af52
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:80329314b3d6ba6d19ea2dca903bb6ed28b3468c97914775434bcc9f0f53350d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:67ce3b727a09ad555db7e6eb43282a11bd10d0898214fd5afff1a3e30daa065f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:080baae2f4074a3bb1274056147e884f72bf8f8ab43791c8e51cf7f46bf27372
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:ee17399023f765f2c007574acbb5e4227de89834cd7441d6d1f97a66ca695615
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:5663773babdcc1ff5c3bd497a67fff5f8aed67aaa9ec4aaac3bebd2fbfb6a916
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:270fc61f918cb16c7eb5979c9651efb4bc4f1d2fd79b65bdf87bbbf1465e00bb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:68e391ccd21a41c7e55f690bd87377327a102ca4cce12b65f48640df2c3db3cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:1be7c252dd935ff5c80e2175622b7a1c32be5d72927803be4d242066a058e804
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:8b8bb31c715c1de648eda6e7b1f126ae5538bb4c05a476560741462a66c72048
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:0f2611f6f71cf3636d448552a8ad96026379117d3dc8ccc549283583f10fff44
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:c0ff21792f582976f13832c7ea95c2c4da22849a819b8ee0b2423b738c791f3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:cc22de4a9b2fc7c6b282afb93649565828448b91f29613414dee8e6d77ff8bf7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:bc5d7e481e66fa0b936a81c4854cc0d9d7c049ba5d9de8fd93e22c0114555114
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:3d5a0d0719dcc6ae411a51f897af4a2bbb01bab88d0f40c8d3db2fa80c0418f1