Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Copilot) (dev)

CIS
linux/amd64
debian 13
Tags:

copilot, copilot-1, copilot-1.0, copilot-1.0.95

Index digest:

sha256:c77d6b97e1fd377413eb83f599af9541396326647d4a9e31509bae13e9e66b61

Manifest digest:

sha256:6022a980a9227ee53a38245d4b3816bacc9a537667b9726492c735b27beb7a32

Size

486.97 MB

Last pushed

8 hours ago

Vulnerabilities

4
18
10
44
8

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:copilot

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:copilot --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:076f04c83c36aff6b1962382ed02384e88f16f80088421f85645eceecc7ef7c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:420a98b05cf71c402fd2b5e249aaeb162ba2275e2e785037b2d4bee8d636aa16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:8b6473926fbcf66e0d60f2f1e499e8acbd599b2b261967c3846fb4e1351a442b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:fd6aba88bcb8c0e6b7c2c04748ab22298aa40eb7cd0333aefd8d28acd3d44ce0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:666dea4bd2d16ca8db3cdc381ef0a0290e76c2ed464515b9d970fd16fa902d42
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:5bb36240d24d0bcfb369f11885b607cece7f2782ce5e39c0e0af5eaee1cd4961
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:090cccc08d685865d8d7fa1f4b77f36e85b24a909d5d7100147ebc3858809442
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:209aab282b4479831b0a1045408b388577811a41fbfdd31473ac6fbffff8bbcf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:5e2bd4d332520b0d35bc8bfe281087c5cbf5fdc2649b431ed33816032d3c034d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:52fbac76f4a515e29bacdfeeba0e6cdc10bc3fd3d74336025809877bbc82fbc6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:900b6eaac706a91049f5a465d758d047d74374e8b6574609f35eacb63ca25282
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:7d31efc048bfbb045156307b22cf4890c478d52051c68d7ecd47dca41ddd8fa7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:d680d7f829e8907c7a5e9c931478acdc87740c8542301e24597699694082ad24
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:0a9e64bd8c8d294a6a05edff3545f5ab717fa4af93e48eb508f8a3c5123d7858
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:2e8871bc43b146f1eb3ef3018aea9b1969dc9c524beddd916cfad2a4d481c34c