Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Kiro) (dev)

CIS
linux/amd64
debian 13
Tags:

kiro, kiro-2, kiro-2.27, kiro-2.27.1

Index digest:

sha256:09afc4c010ad43878d1db7c12dcbff24070a33458a630fed596f6561a4bacca3

Manifest digest:

sha256:72acaa6518cccf6eff66d3a9c77fd10849323b2cbfd7753458f3cde3e2d3c2e7

Size

526.63 MB

Last pushed

11 hours ago

Vulnerabilities

0
6
11
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:kiro

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:kiro --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:a5f54a1b6e5190f805e84fc812b5978e239aae80cd404d9f2c3569623bf9a423
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:6136f26408cf83a650e0b9495f057e2b5d75c3a68ff630c49bfd68b01133f7e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:df203a0baa71ed513135d314b2fd15454c55fef1b87c12ce73253d39b16e8f42
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:e0f6bd842e85229390e1fe1397bcb235b71bfe365a1145df00e45f765648126a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:a1dda880846c316eef1043fd70f1dc2be334d6852807c6f6cc065b25e64baed2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:6ccdd5c545b639bb47eec843fe1eb37623be15907b67f227507778945a7d099c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:372f3d46e6e4c967e26ccea89a26f8af09cfad4761a6b9c41c32cd26f1f8eca2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:f376a790e1916a62f966c08fcac92baa800f14a7e9383448fcb6875ccc787735
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:77527ffddb2e038d070faa382af40996408273c6aed4890478c110cbef8b9848
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:e54683ca12d916a827b23aab25d6b0c784de52816a871c28d7aef332de273589
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:b168fda798f504af1cd3dd3572fc0f062fe6cafd71ab9f1ef340c6690332aa9a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:c1e5f4646d734967d6d15144883a9ce8eb91291435998edb19e0356375c6fb88
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:858d97e45730946a2e2840d850c33aca798a04ef66546587322f42cdf931bcab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:2e1726bead5648371c18106ee5ff291660b7123e47c78d0d05cbdcb2d5c7b2bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:14d3fb26744e6945f4f8d68bb0f25bec1075a729ae6e90a4f762ca8d9b54c433