dhi.io/sbx-templates
docker-agent-1-docker, docker-agent-1.148-docker, docker-agent-1.148.0-docker, docker-agent-docker
sha256:407f08d154a2f3bfe71742f782ccfa0f694f50c2c04a4d6757d43dade9673038
Manifest digest:sha256:45b8950aa721a60d744d7bc25dac36b457ef0e0d7c8caff8e3852c4473bc0a5c
Size
519.79 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:docker-agent-1-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:docker-agent-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:da96f729d4a238a5b6451deff22a4ae7c604491fdc18e0f872db24d88ad2d7f6 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:8c1f8d220456e40c9296d4a5529bb2fffaf1d255ad617915f6ddae9c0ca02d31 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:ce0440cb1e7db1d9e633d89c42dc3825d5ca8b7d3c3557ee3a14bb6372b03386 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:fcdbbc7317f86e49d108f1e9f2ec1be3d33a6514f08893dd7b98b04f28c240fc |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:7223384e87ba44b24e24da158e4fe26983fde6a0de278f76398e75befb776901 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:7b9a8ec469a2fe09b742aa682a584fcb843eddbca0358c9fd256c0ca8e21aa27 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:36ed248d8fea56cadb7f4996c17dbb2a7a3897610652b16b263de1f0f4c9ea4e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:6608977fc1af303de3b3c67667349395022845c4c5bef93398343f3172f2a6bf |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:766464e9dfe2f9d1ae8a13f2b54930eaa5062e438231f6118e9cf03fdfd6fd6a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:cbb4a1477aeff1bee9e6faa2354e1260785400a615ba6d54d4bcecb2e46e7f8c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:2448279f29c5ba9a01a6b448cd95b55d5ef0ae9f1f49f56a8935f0917bd596dc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:0cc5298d001fbf800bfe8ab2a05428d2f8dad9126e58f35b031228c2a05206fa |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:049fe0176950541b3fd2f942a1ff17aeaa32990f490a347372fb6d14a4d989bc |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:3f11199f56ba9e6487404e45fe1ae4f36974ac581ca96db6ca235d6e9690f033 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:f9b41046430bec83f727c86e8e08459fe00f62d1078a6726d0a43874f2c7cb9a |