Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

droid-0.235.0-docker, droid-docker

Index digest:

sha256:d843fcbacbc58f3255acc779e60997adb017ef2b4c830ac3a5f8ee2a739fdae6

Manifest digest:

sha256:f73df71f91748b4dd20fc2b1e5bd2ebbdeebe429e62e7ec0a040f3973226a6bb

Size

592.55 MB

Last pushed

9 hours ago

Vulnerabilities

0
9
14
50
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid-0.235.0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid-0.235.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:91d52851096caeda03001494aa27d9241a3fdb9a6121f304869ad5d1bb4f74f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:0d5dee0aedc9e7a0cb98139054a3bc3f799d769681bcfdd43ef2a7b5c1b12380
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:87a9731e56bbd8993223f4b205092d89b27566a7bbd3d0641c2dcfdf3df76793
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:88e40fab18aeaa2fe9c1a8a92fc643c1ff171d59d2224774e284662bc509829c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:58db0b5f429a2bfac16a54810d66697014d26ccd416ebbd0b67774ddf10605b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:4e76d256dc9e332f07ba715a6326b9b61e23691544532b90f42cbf7e31f378fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:217e7b122df088df197ed449ed36efb13e32e7cfdcdc8f88faaa5fcb254ad6b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:90c24e180f662c2465dc88193694794c977b68a273bf3233497a4c7315b20955
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:36da11663a262fddef75034b10ea1fd7ee5e797713da29e3e040bf7035735133
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:a6f2c0f2d28be4f4539ccc39b7208af43c4842eb8f65fb256871ae7e0fa20e92
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:792c4608d58ecbdd1ec061657aa9d31528ecf12f5cb9bb89bb54e09416d79e35
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:543a341a4fead3b67eae52131247f262932db7338aa1ddf6f66b405e8ed99169
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:5bb2f30749580a3e2fc22343c03a239c726fc6626592e92a3388deac0e1aa9bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:d113c20ff4692cf79195f1708859d61960e18d4a5c3028f517b17c8347febe53
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:511740e269fafccb3d5108bd68d94ea93dc964af041c8589f9cd1660b0c46e3d