Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

droid-0.237.0-docker, droid-docker

Index digest:

sha256:3969bbf516f24aa03efc7a9f5111da5a750af4626f77a0b89020d1b0cf0ac3a7

Manifest digest:

sha256:c799be73e8665421567922b4f2acba121a4a7887e6cff4e70d632cd25b1437b9

Size

591.76 MB

Last pushed

11 hours ago

Vulnerabilities

4
21
13
44
8

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid-0.237.0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid-0.237.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:9d6b793936fcd2211abf2e5f968c36f07d894cd987695c2c21c58c4b712c87d6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:977347e9723c735c5b7b969ae3873ad08c690cdb5acaeb11b4c724fd3ed0e078
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:f45f47267925ae0c4ae773232ed3077ab2e76b924a9c1ef446d63c9c0a8b84a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:54af8b9afcdba997b061b12aa7826cba6ac843f55940634800ad420e96859f71
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:ad851e68f1cfdaf55c135b5c17c416047f84d44bc9b4c54ca9f57783e61c10ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:a5af4b1e44a25837ceba899e3fa8494ef5909edd8a665a825f39d8790886e313
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:7eeb38001ebd28ce29069bfa01a22c5cb582144f2bc197a5790d6db8b0c2bc43
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:37e94b9cea2c6d99205b914f16ccdad0b64c931cea4aaeb2a5c25c6202563e6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:6185c77457aad383d0bdeeeda97f0b398fa0473e30b25c2f739f44b1abcabb8d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:ceddf9107582e3852b06c1765854bfc95d77f1edeb9f5a0935e087a7c6100e1d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:9b61901bef66a2ec6ab70a0a1a44ae78544800cfc5c71ad9ffac1c08367ec967
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:670c814a3860b8d038531126c4cb8e2460406354cf53da2a445fcc1e8df6ff95
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:223d72342ebc065d014b24696dfdd3124bdc8e96fb65b43da6905642384e59b8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:0a950b2f4582c67fb837bb0d115e12c97930fa2ede5ad0469d8d18b48ee437f7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:c2fa16c83c4a13baca199b505648cb3d28e26fafac96840f4f4653004f84cb25