Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

droid-0.231.0-docker, droid-docker

Index digest:

sha256:cf3207c2c7dcca1f3a7e815870e8c6fdb070805b64a462840b3cd64e08d9f789

Manifest digest:

sha256:0b8e6d06fff4a6e1cd52d152b81a1326785667ccbbfe2b26e7f67d4665d961a3

Size

590.92 MB

Last pushed

3 hours ago

Vulnerabilities

0
9
10
42
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid-0.231.0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid-0.231.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:9b00e55674c6052ddb565fc75974718d2f37eb1da747554d53427ec1b9cff601
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:4961cf4b1ccc62df2e5cb9687cea20d335b1cd20246edf1a85f9308f94d51624
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:17a5ad40cc4b439012f1648a96f7b29b338fa4ed6531268ed3560414c2c9e57d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:8695d8cbfff39529c44743cd83eb6be6eb727347877cf1c234cccce3dd74f278
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:da9b4ae3d11e54602a3215250fc428bf3c6a7fcf079e07dc01b5fbe61444e9a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:46d95df79f618fb54cedb031ed5a4abd9831ddc419d018ab443be94bc0f66f77
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:bd25922de788e7c18e6e823b705e1d2e4bf7b2c4a7da0c86a72e65061e3a7fda
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:aa09c57ffbe228e6fd5f3f8c3bbc4dca6f7a327e3f254d49268f8553d4dad464
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:d628051eecdcbb379d10a9a0287d6c43c10822a27fdab138aeef822bf6194764
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:40847e7096982b4ae471969ff42040ba0db86a0a209ef0b951fb3647634a236e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:bd36237739e1d0df68b910b67f500dbe0325df479663546910447c169c9f4aaf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:2983e2ac9d93c162e16899f1a61f4e51ab29a515f380677afa71e1926bc2697b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:e31420ac7820971309bb50afaa3013b6c204038bac1a09aff1c9e6d0b11831dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:f93e62e0409d194295c1df3d2e40d77aaf835f2d42b9122ea8a61fb9dd0b917d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:7838802d36a800a8eefda8f45c0835cc54c45c4ef3211dcad5a6102b33d2791e