Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Docker Agent) (dev)

CIS
linux/amd64
debian 13
Tags:

docker-agent, docker-agent-1, docker-agent-1.140, docker-agent-1.140.0

Index digest:

sha256:9dd1759c324cb6043260ea0f04e66810ddda6b61c4b3ac8fee5e23b02e77d764

Manifest digest:

sha256:b014485db3bc8eb62589da0a4efc81cbe734b202f4288665b2fc233054ed7f86

Size

416.66 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
1
40
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:docker-agent

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:docker-agent --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:929ab0e6b1678c3feb6eb1f98603be08bd96fb67c452a24e12f9cf613b405d09
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:06bc5a87e43a2b40d97cc1fe076696e61fe274f94112573a4e3278504ebe43ce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:91f1082cbcfecfd9682b669789f43cac8877c0fa7b6aceccabb0a99f7a0079e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:f4e54d79e3772a553ef0940a56f16adec4873db8e3736e80d6a925852d5cedb8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:9e08db7b26a5cfbdad7994222bbbdbef94805ada6196aa42cba9ce4df148da60
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:892122946c9c1641d12fc1215ab2b1b144f1f928623f63b11c5625241813eccf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:67f6cfe8f39ef5c8c86447e9107fdfe5f7a024a2ec8fe70efa88b09fccd8c8e9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:e95a89f123446a80b92989e0bdb424a54c47e4254956d12db8e2b5975933a913
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:fae0200445d3f55176fbc997845c0a3bdc93dc5520f38fb4647a32462c03c460
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:3f5f7bc3576eb813900ceeae966fe2c595e0f5e98299d692c2b7e7f70ce30cd1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:022d71c6cadf4bf8a2cfda8f225bddc3f641dd0786f36901f005614bcb218678
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:bb65c248eda1b3a8c912192e81b84877d87af926db8c282095fb527d379bc64a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:ce6267aa3f80e77c422c1f30433dbd2621a5bcf65b6a87b6ff042b85281806ea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:58c7051a262776513d2a25bf8027559e131ce79d0e2f685e2229abd0a1d4ed99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:2771663b2752a6cbf5a76f81fed6cdbcb57eea485922d275491dcecac8299da6