Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Kiro) (dev)

CIS
linux/amd64
debian 13
Tags:

kiro, kiro-2, kiro-2.28, kiro-2.28.0

Index digest:

sha256:ee05ce5ec141d39c7c91a6fd854d6af572ed3d0a88c6ad8dd826c720b6061407

Manifest digest:

sha256:2ae4e2e58a96ba9494bcc4a8a22f6796ab797a49dc7a1f7352e4155928a14abc

Size

526.65 MB

Last pushed

10 hours ago

Vulnerabilities

3
19
11
43
9

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:kiro

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:kiro --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:82bee1de76e6671afcf09a20899eaefee364e2c1e8c165576e446ed3aeb884f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:57316dcf98f3af17ef0ba5a3b863ab77c9abd34b44053d44a7ddca4304b731db
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:d3077924b673eb77b471dbbc44d41fbbc830064ccb14248d6f25b5021c884b54
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:cd267104d7dca50be5d2a627a513eff59056fcfa603027ffc3c8dd31adb6a126
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:e9b6fb972e84932992af6564732eaa982bc2a9196e311e7db9695a5e37dd479a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:1f50f93612ff5dbdd2c5092556e48f367d8ef9dd85031aadd64a2a9cedbfd99e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:279d37e73907f59148de625b3a378dfcf6112bac3484b25044752c35eddb61a8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:dcb9824cfe0a9845b892d687c21275aff31c92aeec08b542d6fa693ba3d25f0b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:53a6335e3af03035280f6867854a976d6fbe9339cafd77233a5681013c0459d5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:b7ec8dced148c97d8d4b7da8d0d979cbcb1d56611f96afd1ac5cf93a2862d81b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:56a815f42a32bc7d5cd57cc84fe75153f4b462a07297388289ab077777be53cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:3506992d9ffa7dfb219f14620b98630c547ec67ba7c1cfcb536c70f963d1efdc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:7dd6380b93146534abc7d07e469640b70049b7cc72a4852fa56d18aeb0c3c1f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:785135604cbc1bb4a20e9ab22b8477fc2fbb4930ee1fbdb3b2cd285bdb00321a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:8470d1c460a776dba8ba7cfd161fdd92875408a587cd7a9fe3f2a9e53e9aeeb1