dhi.io/sbx-templates
droid-0.231.0-docker, droid-docker
sha256:cf3207c2c7dcca1f3a7e815870e8c6fdb070805b64a462840b3cd64e08d9f789
Manifest digest:sha256:0b8e6d06fff4a6e1cd52d152b81a1326785667ccbbfe2b26e7f67d4665d961a3
Size
590.92 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:droid-0.231.0-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:droid-0.231.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:9b00e55674c6052ddb565fc75974718d2f37eb1da747554d53427ec1b9cff601 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:4961cf4b1ccc62df2e5cb9687cea20d335b1cd20246edf1a85f9308f94d51624 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:17a5ad40cc4b439012f1648a96f7b29b338fa4ed6531268ed3560414c2c9e57d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:8695d8cbfff39529c44743cd83eb6be6eb727347877cf1c234cccce3dd74f278 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:da9b4ae3d11e54602a3215250fc428bf3c6a7fcf079e07dc01b5fbe61444e9a2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:46d95df79f618fb54cedb031ed5a4abd9831ddc419d018ab443be94bc0f66f77 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:bd25922de788e7c18e6e823b705e1d2e4bf7b2c4a7da0c86a72e65061e3a7fda |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:aa09c57ffbe228e6fd5f3f8c3bbc4dca6f7a327e3f254d49268f8553d4dad464 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:d628051eecdcbb379d10a9a0287d6c43c10822a27fdab138aeef822bf6194764 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:40847e7096982b4ae471969ff42040ba0db86a0a209ef0b951fb3647634a236e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:bd36237739e1d0df68b910b67f500dbe0325df479663546910447c169c9f4aaf |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:2983e2ac9d93c162e16899f1a61f4e51ab29a515f380677afa71e1926bc2697b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:e31420ac7820971309bb50afaa3013b6c204038bac1a09aff1c9e6d0b11831dc |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:f93e62e0409d194295c1df3d2e40d77aaf835f2d42b9122ea8a61fb9dd0b917d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:7838802d36a800a8eefda8f45c0835cc54c45c4ef3211dcad5a6102b33d2791e |