Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Docker Agent) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

docker-agent-1-docker, docker-agent-1.150-docker, docker-agent-1.150.0-docker, docker-agent-docker

Index digest:

sha256:4b2b0889c746f207a9a90a0c04dcbdee79b39aa471c6da14943a95de580fda4b

Manifest digest:

sha256:f9ce86c6737dfb4d5879f6e6e3ddfc99b0a15d7c9ab155545d89e767b0243a15

Size

519.31 MB

Last pushed

10 hours ago

Vulnerabilities

4
21
13
45
8

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:docker-agent-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:docker-agent-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:508647dfe4e95a62c9681e7962366200e243a5b66bab14f94a973d2bb7c1fb22
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:089c6ef01684d63e942bb33dde13ea8c5c1934e00903095e3ce7f45ba347a454
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:5cc4f482f34d9b85d193d641ebe9e9ee92a99d7b762efa477292a5927f946edb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:c5fce4b54bd50375a843e720881428bf108a4e7f75b693e6f790173deb8c2c03
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:220ee4f6d71895407e6add71a44c52da2eb0925b45dee66828e645e3c5e01b29
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:ca3035ee2d8ba167303728dd5d90f5f1334b5be237dd78d7669585068f1f0399
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:0b6ff63b5cba395189a1b31d5cc08e2fcd25d111e06cee087325f21bf1c73dbd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:f52ccf4e88ed48426f4dce1e43feaf0664b075f3fca718797fa15c9a428b4239
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:057ffc3df6f1b15c30a0466484dcbd6bf6e2974788c157b4ba10d778325e19e3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:6f995284d274c9cc2d3b9184f5e6aa3256f51e8505c2bd1667ecc47b662f1c3d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:b109e43c726ba8892108c8d8de781ff26af67a2c5d2b4a2b878b4c6d751a67df
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:9089baabdc030bac5e3d495d7616eacf9fc3fa4c239f0cdb596c720cd30d4731
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:0e5e4dfc50796ca17cf0d59e1d22cfed4c08adc841bc57fa215ee9245b1730b2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:75cb6bcd5b6e3239121185d986a71077079d19bff368f68d6bcf153eb8b1a1dc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:6375eafbdf695589221efedc16f78b987f8931319bb412021052917a4dd4d305