Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Shell) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

shell-docker

Index digest:

sha256:ae7b5de0aa65b841b2e6a1b557adcc598562db083aae8044640a4be11c932061

Manifest digest:

sha256:0730fa91eccf615e14caf9c41bedde59ae0442b4ef31f1f4b4ab8d1bd141381c

Size

485.68 MB

Last pushed

10 hours ago

Vulnerabilities

4
21
13
44
9

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:shell-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:shell-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:14421954d5af1e8350a2120a15bcf5a3a2f57e4925873acb69e90bf6784b6951
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:20a11a4e0f5e2fa81403361a3b23985060e8cb576259dc01f6a3989cb3034bbd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:7d4057c38d2c2ea01e6b92590561c446a3a288662d3e8a006a97c8aa513744fc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:eea615d17bca11615685abae88a1ebb058fd056d798c03e4ef7fb10a8c67b30f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:de2018aa527a0b85294d1e1d036993da9142f614c49db58d61e9801c71a48da2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:2c2c3499727ce71c6cfa6322e30cb9232c5fc49e3c28d0ed92ecaabffa0a6433
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:920415d4af4cca8aa14608eb230a6dea5eccb9af5a64928212446f6e7cb452e7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:a4ba71aff88ebd907dd00ce5ea75ac089d66b7916aef8f41b8705fc5110f9d4e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:cf448c8c3fd0440bfbf5de60ace824765567f83cd127b7409259ecc8fbb2840c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:5cea126eb816f2eec5ce2050e30025d89d58599684ac2a022b78476e85e5c0f3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:8c34071fda855da1056d2409a7afdfeddf86ebe990ba147b16d521c4c1e4b313
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:a566a0cfd0af22fa3b1581b1a7bd5a78371f66a6b488021bc3931b2454e0a409
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:3d3813b9cbfafa7e3b8a97706bed857040411637341a8f746569b6d16fbe8370
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:1eedec8e3b586bc5f18712ea4315d6f78f9ed5bd00277e9e2f4c553de3e1e747
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:04a5dc403955ec2b16749cd3ae6770b24705b4a5b6601ba4b03e350304bf9475