Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Docker Agent) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

docker-agent-1-docker, docker-agent-1.148-docker, docker-agent-1.148.0-docker, docker-agent-docker

Index digest:

sha256:a0571831bd278f4871cf8ca854bd965820e354ffb2f911bd18e88740c7b570e4

Manifest digest:

sha256:9530a4ce561fb7e589e7872c6cb3ad9d6fc78182c13f01c2ca226d9778fb90e1

Size

519.79 MB

Last pushed

23 hours ago

Vulnerabilities

0
9
14
51
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:docker-agent-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:docker-agent-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:9d8341764cc4de8cb0b91ca2324bc92759a1281214a6437fa73b5d446e5882fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:d24355e5124884be8a92bae215105e0e72af44968f51b64011aea04dadb0609d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:4b8dc95ff0689fa4aa9219cb14dc9fccfe62f10fc872422cc4bf3479723df123
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:63ee95d05ae74aa2c49a8c13ac6e2ccd5fd44665f25d732ae9790e688e792e31
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:21d91704c4a60d9de5ec84e01b10e6cefc85f69ebee7eea4d057a0642f14dece
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:14b5ce88d796cd803df54e2fffafe8cb98580f604fd19994c040fe20a9f9dfa2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:c2a6da9c1d4acb73195d20eea60d0fc197b555b5aaf81fe6945d764791276569
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:32346928fed88ee349d47ffc7fe2b3caae2cc9298fca291ac197dc5f4eeaf896
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:7e67cafe23c9caa066955650c9cfa7e8ca02cb7faffcbf15c9856400765b6388
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:a8a788f7e4b21c4af24f66bed977c6c06d64392f1ce4030d515b1d2b40be9aad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:d11d955ef46f69a9b3a23d1498c85cbbc81c79576461d4993e5cd439f3bf9ed1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:14503ad01f0c1cae63b936351c7f1867ddca42e7b147ecf26fd62896455a4356
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:ac72fdc07b0c1858ea1a39a4e889092c0f5a8d460f6b419a57a7145ac6509a48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:f52eee0f02e946e564d9021c73ab6d07c7d8ef273b9317bec79e4cc09d1a74ce
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:9ee3bf1ea70d93d1042b618e76f9108c2fceed71319032c8b5cc2c97819674dc