Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Docker Agent) (dev)

CIS
linux/amd64
debian 13
Tags:

docker-agent, docker-agent-1, docker-agent-1.148, docker-agent-1.148.0

Index digest:

sha256:1224e1731092aa1f14f54a949d47119af105aa241dfc7cb1f1bedea7933d8ed3

Manifest digest:

sha256:1800ea12903b9ca3b0cf72648352317302b72a9d5a77cc2b710be44c0068f63a

Size

418.39 MB

Last pushed

10 hours ago

Vulnerabilities

0
6
12
45
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:docker-agent

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:docker-agent --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:d35b0b2ed3b7e673ac00fcc2903985c2dfa74c092acebfc85215b22a817c6a53
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:c931d6bb9a071270da648cec71d1fc8441de4f0ebff342eef053e191c645c7d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:a9ed81b7eeb313050cb7d9f7625ca59561659fddf8225b3092a2c92d744947ca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:24ab24ec77ed5c474112eb853562bd2734aa372f0755b05e28fc90dc7ce21080
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:55e28969352638485f269cadcbc1dfce3b6ff144de149eff6c0ce6959f2ae726
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:610b024909e8eda414a3d0225ea1dcccb0ce3113f2c1ce971ec5e368fa938e2a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:aa7cb409ffb117399f56100c41fec6e0fb5f6ea2659e590aa31e02fb49483991
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:ca8ac5d05f67da7e02f67bfa344b8fc6f67342ba70e2091ae2365d559eff7a49
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:8fbb872df92da5844bfbf1bd3d5fb0ed761a8893513ff2ba160dc24b4519f4ed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:e0317b9371ce0d8d0d5379a1cf5b6d0b2604437877a1e31b3512aff08a8a1093
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:510621061e06af60109703dd0d23b8b1795f8747d06bed15599f7b49eec10255
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:52b0ec025cf1486539a73f853dbb8fc87c174a7386d6f1b5aeda0fcd73eae7ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:dcbda405984302371a229d7d074590a569d7ef0554504e2783b3c753003321b0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:21ea8546dd44ea49b757b2f47e42685f607bc233af323122ab48fd8c71664d56
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:f45020c4c2324143bc0d020ce4a0f60d827e77779e0f3690d4448bcf51199564