Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Shell) (dev)

CIS
linux/amd64
debian 13
Tags:

shell

Index digest:

sha256:d219a2cb9a50a336629a996dbf4e46de47d10d549e2f042f3376e5003ed53043

Manifest digest:

sha256:744d87d544acc7a82296dc0f0bb701358175d1a35bd5d2b048310102bf1492ae

Size

385.62 MB

Last pushed

2 days ago

Vulnerabilities

0
6
12
44
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:shell

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:shell --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:29db0de09f4d193cb2a69139ed3f6419bcc34392b6cef26f0113a00c6f309107
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:be7bffacee306adb4d8ddcc55a0cd8cc1bacdc5fd896035f43d9552ed2596d9c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:0032366ff83c9b9347ac6576aedaa94fb4ff0c9f3fc0ce6fc5799f3d20fd848d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:35bd9fb0f262d5c93a801391555faaf8559b0376c61baab50ac7b1ebb9a3f24c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:cfec599af62ccce1203a6f12354409edee6f7c5b22314d1b6c1bd0da12480165
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:1bb26e781f41ffcb78d3f11c17d97fdf9c3abb9f5743e6df106913a21fba3d9f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:d82750880a55c9c89d898f784f0d130181444a8084598f2b16bebd26e1d5b1f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:7ff80dc491a8396512e39c0c19465d094d63366d18fb73f87cbcdad9c6d73c52
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:cdd02833a7575e0890c2d16ee98cf11a1bc40f3f2c6e516d4f74703a96673852
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:f58905f21819303f70ff2e3e558a8d071fa4170bbbc0b2dbecfff436f5640797
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:1eb019444adc3b1704ec0be9e8c924edb652177db4b2ee084d537b2e907e2452
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:d725ed4a3b5953afee359060bef6fd0e3d81c24d6d2543c4c9600856211a95da
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:b8e638a11e6364f3ea5a4c435aef5b644d9c6a4b656cce61c0fd2a43efb9d68d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:98d9d68059477baeb616dc17a63d0ff875003ac21c6097ac516344a6b4c68cd1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:ecfd7c18ddd9d6842ea452d53be7e8aa7e10189250ac8037237bc930a3487af5