Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

droid-0.236.0-docker, droid-docker

Index digest:

sha256:dc2909f934f1a11f6500168cc8a8177a12adfa8c68ccf21ccbe28cb062c31390

Manifest digest:

sha256:a37c8c5db2cfdda3fd2a0400d3bc6dc9e891089b9d0fd507eb8348e48fa41edf

Size

593.78 MB

Last pushed

6 hours ago

Vulnerabilities

0
10
12
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid-0.236.0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid-0.236.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:2fe2062362a2c91a0d3bbbace2312569911fdeb7c6121d435ca50619efadd145
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:5f0ff869862f461fe267e03569669f1061d21939fa28fa74c818b4752b5dca26
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:b7447fa1321151f6353e87f085def0b074f7c3c5c7a07b0ea41bcc053e5f6dc3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:b5ac8073a79240407011833380ea741ecea187ba6dcdbe27716b069920b17cf5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:7e54c9778c9d7ab08d28b34b6222c0bceea77987aa02627bd7134c246265cbb4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:8bd7b2c33b40e4858deb1cb5e2bf7143db31a93dd314a237192de895dc63b23b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:4ad175001eff8ae4496ff80e7d3c95b058b9dc0cd9ca0831d13d9663d270c735
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:40f87707e5f784c775bbeddf46c056155318577c67bcb1e5184bafb4aaa467a6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:0ad6f31573d4302e9989f3252bf94c6699caa40ca8ca4cfee778ffcd3c14b196
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:d836600076e57e82c10e2564d67059b07aa554b39d5d9c785bbfeaefb2cb769f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:026de610d011f6ef659d7e11898d9780f04f2f90a69d60f8aa85378d5b0626e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:1edd6cbf32528a2ed52bfe0cb164fd1dec68790fe895dc855b345f4b8ee5e5aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:c89ad66ae4e57a6f505c08dba64eddcdbd5710fe06321e014ea91b783cd5d6bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:451bfad196050d27b91f58bfde122a892eebae1c91076dcd1c42109066feb6bd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:12e46c804da298b3ad6cf4b7b91a557bbd384c77e8347d236847bd8768f375fa