dhi.io/sbx-templates
droid-0.234.0-docker, droid-docker
sha256:2cadcedc0b65e7911ca42b758f2c19e2597c0c0b414f4596ed5eebcee5898aa6
Manifest digest:sha256:08c757d905b6a6c19c11a4d09097e4625268ee092c651631493df660dbd4fea7
Size
592.15 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:droid-0.234.0-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:droid-0.234.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:6d8a6682d65aff362616c5c282a0fd6ff3c8d41ec92fbbda4374073937810a3f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:ae9509ff0b495bc53dbd9c76f5810a15a47af5eff4d3eb27943e9f593bb873cc |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:80c32a5395391da61c9bfb2ff0f80095386666f306d59796fa472be4349be502 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:c50772edaa91439f0ba31ff052c3768cdc02fb12fde9bb20690d86a80122682b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:85430c679889accf1168dc4a1e22f4570017d13975c762ae5e1dac0772de4efd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:ca041061f339a0a57a74767a14f3e12eea494ef49fd65586796efdf9548c01ed |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:9ea262b4a370c55c2c0897c6dc4d248bc2a91a254f0e7bd57ff5b7630f531975 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:143922367d1a00c5167e5d6da060cea2800bb10e5fb80696fb27cf2d381e964b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:b8b1a8754b6e3d51fb7eb85e3cc4a6e373aca4015f27232ae1f8e371e8dc1592 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:eabb60ca1e5062492c064c81d895bae42903ebe85b9b44c8757cd2779da77e1b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:7eb8f83aaf20b4cfafff55224d79e5e9f6223a8ec9d8093a2776eab15a78f404 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:76dda0d5b38df436291d18212414ec1e133d2ae8ed73570787a86a27ac70b0c8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:3d39d31c99ed512d93b4621fa2e4518527295e78f4d7724904f0f073f69abb27 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:b2d12409ac93828628b4730e97617c7d76b64e5d0ae06ab9b387a181e4bc80d6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:1a764e7e33e1666de669dbb239271c846ed783b3ea7b9f3c70935bcb73697c7f |