Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Docker Agent) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

docker-agent-1-docker, docker-agent-1.145-docker, docker-agent-1.145.0-docker, docker-agent-docker

Index digest:

sha256:41678728bea2d39928104598ca6d8e09ebdedf6c688e0437d7d24fbb74eb5f39

Manifest digest:

sha256:3f19219bbd1ed87e3156d376bbe9092bbe291759b26e4e7b29130cef52af890e

Size

519.49 MB

Last pushed

19 hours ago

Vulnerabilities

0
10
10
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:docker-agent-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:docker-agent-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:01e2af33ce6fe4e2428a891dd9dee473cb8a036ca89f9d8d9dec65e81bf118f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:6cc872d74e3af4a28271933949baf2bb2bae98995664f0058718be09d4bccebf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:17878654b6fdf4d3e4fe7dc2cd7b9a16487d036af05f01b0cae89ea4016ca3c4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:61105f38b5137c1a47acea77057a2eb81c778b7d44af5d904cd1fb4db9682153
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:acf6121cd6c1b2cfbfb10037e62dd758b7813792b14c07da6bf9d2753f9921f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:83e175030944459cb2e4e815f229495ead67c1dfb1e5fe7a78dec93ae0bbf858
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:ebacd89413a3750fc23c319c472df5fdf11b7a49f3aa8f194c529a359f4d1160
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:7d9b851a414a9df70421b44f05be79d502a4846149ae6045cdd180185bb0f736
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:4aa497dfb02478efe06fbaf6736e440177c06b39a61ebe9446cbf5d431cc9d1f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:4cfd5cc91dd881757e14941aca30ba31348cca8748b92ee4d915f6d9677342c9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:7b89801771eec0c8bd32b775d2b3b5e862e49883c71776a736d4f14246b0ea85
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:4c085e00ef0c15acfdd58664fbb55611e4bec9de3e22116ab8e6bda4f4b1ea58
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:2659d51a66b0c6accf2dc7254f07ee2418f2e2498ebb5874589b7ea8989a0ac0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:198f6980c0d4820a4baae69af8d4aac631df17e11598b411632ddf49a90cfa6a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:788c218c37bf806976cfeb4a839c9dd8ed0a85906d82c5929e529566ca618958