Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Docker Agent) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

docker-agent-1-docker, docker-agent-1.148-docker, docker-agent-1.148.0-docker, docker-agent-docker

Index digest:

sha256:407f08d154a2f3bfe71742f782ccfa0f694f50c2c04a4d6757d43dade9673038

Manifest digest:

sha256:45b8950aa721a60d744d7bc25dac36b457ef0e0d7c8caff8e3852c4473bc0a5c

Size

519.79 MB

Last pushed

4 hours ago

Vulnerabilities

0
9
14
45
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:docker-agent-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:docker-agent-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:da96f729d4a238a5b6451deff22a4ae7c604491fdc18e0f872db24d88ad2d7f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:8c1f8d220456e40c9296d4a5529bb2fffaf1d255ad617915f6ddae9c0ca02d31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:ce0440cb1e7db1d9e633d89c42dc3825d5ca8b7d3c3557ee3a14bb6372b03386
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:fcdbbc7317f86e49d108f1e9f2ec1be3d33a6514f08893dd7b98b04f28c240fc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:7223384e87ba44b24e24da158e4fe26983fde6a0de278f76398e75befb776901
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:7b9a8ec469a2fe09b742aa682a584fcb843eddbca0358c9fd256c0ca8e21aa27
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:36ed248d8fea56cadb7f4996c17dbb2a7a3897610652b16b263de1f0f4c9ea4e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:6608977fc1af303de3b3c67667349395022845c4c5bef93398343f3172f2a6bf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:766464e9dfe2f9d1ae8a13f2b54930eaa5062e438231f6118e9cf03fdfd6fd6a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:cbb4a1477aeff1bee9e6faa2354e1260785400a615ba6d54d4bcecb2e46e7f8c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:2448279f29c5ba9a01a6b448cd95b55d5ef0ae9f1f49f56a8935f0917bd596dc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:0cc5298d001fbf800bfe8ab2a05428d2f8dad9126e58f35b031228c2a05206fa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:049fe0176950541b3fd2f942a1ff17aeaa32990f490a347372fb6d14a4d989bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:3f11199f56ba9e6487404e45fe1ae4f36974ac581ca96db6ca235d6e9690f033
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:f9b41046430bec83f727c86e8e08459fe00f62d1078a6726d0a43874f2c7cb9a