Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Copilot) (dev)

CIS
linux/amd64
debian 13
Tags:

copilot, copilot-1, copilot-1.0, copilot-1.0.93

Index digest:

sha256:7cfc8d23fc981ac598db1b15f549e89c880bf5b28f36c89a35414713fbad1c69

Manifest digest:

sha256:0a54c25cfeb9e475c4042d54a1a141ae39637526691e6a2040b96265772e96e7

Size

487.12 MB

Last pushed

7 hours ago

Vulnerabilities

0
7
10
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:copilot

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:copilot --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:a04c2b28627de796cf14c71500043bfc388dcb1851a7f11a1f36994da6dea91b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:d921c25a3f662fcb671534dca3ef8ee5f55736205ef0b97b905ea0ba15b9ed0f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:2dd291570ef3bee03b4685154a98cf0e3160f4bbaf5f8617b32da17a17cc1e93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:f9879f40b42c3acd2309d41756b74c32269eb1957b005b1d794605d6833af03c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:bb8f23ab672160056167e332062d44de9e5ebf2c9ce5973cb2b125847404b8ab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:7f509056f2ac00521ff7c7524b7ec5bcf14b851534994d4e65a9f73057745285
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:4e65f3c950db0918dc41b8fee57e04e5e442fb6b6d0ed0c6a13e4e90c4ec86e6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:a12ca906bf88da2a31768703143b1a365a679823e5bcb03c7e6bb6f044770513
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:d1ec3b30397e06a3675e35f94c3fd2433c1c881b66574eb7c3ab39ad04277f0f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:e052abfa9047b03556cbc87a25f7034b77c8820db35bd0cba349b5ed1c4538b6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:6f7745964d57420c70bff5eaa42c8cafd5e90724e9e0a3919153f7f2a22e312b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:ddbfa64847d7f832a12ebc07573ed578768be819a85ebe34211b0374b4c54f02
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:9b67d0e1bacbec26fd9ae54391ef01c03643a61aad0f9f9cfa9c7cdb98446555
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:b71f4fe5a6d5e782aaca676a2f06a7deff3930f113df3a458a301527dee4de44
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:89e0610643fc27935d42a733ebaf9740849258e36cbadba8587595eec39f6784