Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

droid-0.234.0-docker, droid-docker

Index digest:

sha256:2cadcedc0b65e7911ca42b758f2c19e2597c0c0b414f4596ed5eebcee5898aa6

Manifest digest:

sha256:08c757d905b6a6c19c11a4d09097e4625268ee092c651631493df660dbd4fea7

Size

592.15 MB

Last pushed

1 hour ago

Vulnerabilities

0
9
14
50
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid-0.234.0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid-0.234.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:6d8a6682d65aff362616c5c282a0fd6ff3c8d41ec92fbbda4374073937810a3f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:ae9509ff0b495bc53dbd9c76f5810a15a47af5eff4d3eb27943e9f593bb873cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:80c32a5395391da61c9bfb2ff0f80095386666f306d59796fa472be4349be502
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:c50772edaa91439f0ba31ff052c3768cdc02fb12fde9bb20690d86a80122682b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:85430c679889accf1168dc4a1e22f4570017d13975c762ae5e1dac0772de4efd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:ca041061f339a0a57a74767a14f3e12eea494ef49fd65586796efdf9548c01ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:9ea262b4a370c55c2c0897c6dc4d248bc2a91a254f0e7bd57ff5b7630f531975
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:143922367d1a00c5167e5d6da060cea2800bb10e5fb80696fb27cf2d381e964b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:b8b1a8754b6e3d51fb7eb85e3cc4a6e373aca4015f27232ae1f8e371e8dc1592
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:eabb60ca1e5062492c064c81d895bae42903ebe85b9b44c8757cd2779da77e1b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:7eb8f83aaf20b4cfafff55224d79e5e9f6223a8ec9d8093a2776eab15a78f404
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:76dda0d5b38df436291d18212414ec1e133d2ae8ed73570787a86a27ac70b0c8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:3d39d31c99ed512d93b4621fa2e4518527295e78f4d7724904f0f073f69abb27
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:b2d12409ac93828628b4730e97617c7d76b64e5d0ae06ab9b387a181e4bc80d6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:1a764e7e33e1666de669dbb239271c846ed783b3ea7b9f3c70935bcb73697c7f