Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Gemini) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

gemini-0-docker, gemini-0.62-docker, gemini-0.62.0-docker, gemini-docker

Index digest:

sha256:277806963f238000468d85227e7456c0fb265608186eb5967bde5e563e94f1c6

Manifest digest:

sha256:9aad046e3d90b7ace8a7520c2c42c8b7a720de50a80fc9b8ada0239ebe154aa2

Size

502.85 MB

Last pushed

21 hours ago

Vulnerabilities

0
10
10
42
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:gemini-0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:gemini-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:d55e095dc5fc1335b2a45034eeb07fe6b9ab976c56fca736752e11690058db04
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:670c8eee9f05e6036b3913444df09cf5d83f273df0bf1e26ef16e4f1303cf448
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:834c6f134e34bcb0e85ca15dd345e3c4f5c4dba654db2316b52bb0fd3e3f1bba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:8ede04bfe8312d7e340e2586b75bab6202ff0e41d539b86c55872f5026908816
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:444a35ee57e7616552b037d3629624dc094d670f25462f74133cabfd9926e303
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:11177d5ea69fa1d059ad0164526e76bbfa7a654bbf1e5493bdca0531e6c671ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:716ca319af30781d73a948a2bfe3119a194f66f337cc4e3fde087f4691c85c59
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:7825effec0876df5ee9665dd6267306460905cd165648dc7c84a2e45e5f83d2e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:b8476fa99cd90d62992c2f63f3acb1ea1b3c031d755a066180edac0d805ebb4b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:2156d33283a2b1b95a2aae6b5939dfaa0ea600e5a6987b5a96d4f3d4151149b2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:628bbeeb91be436adff8b46d00a1210435ebdd09dbd0d3e3e354aa4e49cb175d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:3f02c7b9f71ee9c696fb4de268f5ce340c1b99c765ddfdf65a738a5582b1bed9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:5cc90f3749f14a2525b9c609c7734fdc48cfce6ed704acb58afd162b8936ba68
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:3c16b3d178f75d3d83f27747f7d95ffe74200eecf07b566fb4dd285438ff3005
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:f4ed265a5d9e81d8558455a1c4ab7ecbf0be6214d5ab665ef0109523ed7a0418