Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Gemini) (dev)

CIS
linux/amd64
debian 13
Tags:

gemini, gemini-0, gemini-0.63, gemini-0.63.0

Index digest:

sha256:208541f9eca9ffc842d051b376d3e9568a5c02491062e54330e46e2635e52e0a

Manifest digest:

sha256:c94fdf8596659ea4c9bbd7c9c0fcad579a01e765a90a436d30e30324f66997ac

Size

399.57 MB

Last pushed

14 hours ago

Vulnerabilities

4
19
11
43
8

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:gemini

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:gemini --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:e669b46cd0d8c5b0528a50debf2d21d98d12e2666ad1277e567b736bf4d7a150
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:fe4bcb1c1d34db2cfc2e49127d454e39a231d8342b8a16a8d1aa66449c0b5851
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:0348510c246bdf71e173160d7907d3b8a9a869c1f95e725ef021ee2dd4c49686
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:b2a029d66ce5ed427a9a5eda0677b272ea31fff89c315be0d8c49bdbda53d18b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:54484b6ee90f92cfd2169d4337938471ec577ef0c429278656732837cb5371ee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:622dc0d26de4acab4cc0208481eb305a617d5193f3c08fa9a2245f1dd9e5da89
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:6c40c72a7710da8efd9933cb43e30ff8122ae2613266d1e834b37d6a876c35d2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:32d37726ae927ce8b230fc60de2d621ca6d7166e586b1578f5f54cd3329b2dcf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:8d497eb0e061164e6e71914c46d7abae599b334e26ba96398c02d059f5a22a5d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:af57207c05813af1058fbb77bcda7f064075d07e1deb79552a971934e3f92061
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:f65bd4f9d564551888caf9da5ce8f1f86c91013fdce89754da50dacc4ed05023
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:1089ae1c6572df2d1a697ef61e9afee75c98b80d629a7011a972eb95eb61324e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:f322712afb5079b4fbe0f98ac6b98586e54dc463b2d9b1e89704f9eeab2c2da1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:f724341c27e8a1665cbfded7ca7c051e6eaee64c849551b155e2a61a3fcbc3bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:6bed9f841f695b586cf7106846d42ddc3231d114127c08cabb8fb00cb1251b68