Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Kiro) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

kiro-2-docker, kiro-2.28-docker, kiro-2.28.0-docker, kiro-docker

Index digest:

sha256:fcee0817e3aa795c98450f6476fab86426895e260c29d27a70281c1e24c111ef

Manifest digest:

sha256:b6502269f22809f1aec26c130df522961a8a54e5cae86a0dda7f69b76bd4ab77

Size

628.00 MB

Last pushed

4 hours ago

Vulnerabilities

0
9
14
50
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:kiro-2-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:kiro-2-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:af5fcda9e6ee93d0ee60c36aa1f305e5939f485609d1704443c53a9f5348f971
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:55d3000a9d37c0ce24d9aeead5e14878e92141469e545aa614793c7182751fc0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:cdfd92853ce6d3996a056db6b74899efa8b80186a9c7ac0c5abe13b50a45b83e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:1dfef2c2cf44f5d06d58da9310dc8beb2fe5ed4a147ce1c587d0246da1336590
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:127539ec064f1ca13adc96f01fae30fa69e039d5b3f7f466e7970c2dbbc674b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:8fa308c41a052249f657419ce66d0dfaeb9a2c2342f7d0170d1ef5585c0fdcac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:5787094ca87cfc80bf56a68bf885fcf29cb2ecb24306561c1c558a303ce081f4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:cff70d09d0d62af8cceb161783824b3f21ec109c62a1630f121a1105e4254006
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:2b5e6bb39f9bd2f9264ae9469b7c97a26277c90d58a6ccb4a6d3592114d32543
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:9a0e7524757be5f1a53906411987e38426481af9486959f11f329cb25dffa31b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:1db7630462c366e03205bf34721aff95f46f8f33a230e56c4be54bf41643dae6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:43c7d5217f7634c15bd71c6bbe8c3bf2f3d2d0c776dc12b9175e7b0d179862aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:ab5702437f0a0a6391f22ace59ac267e0732eea190a7fb4b2360d06ae3c9ff3c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:c463a05f59703ace6d85b1ebb5f13e215aec25847b29bf33ad06d32bd5034e05
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:a32fe8bb18758c3ff8fe574cc8d252bca9d9c110c70c87c427ffc37cb8941b6a