dhi.io/sbx-templates
docker-agent-1-docker, docker-agent-1.149-docker, docker-agent-1.149.0-docker, docker-agent-docker
sha256:0a92207224c5c2336369250c700e556aae9e2abb96bd1d872eaa93c18b1e4184
Manifest digest:sha256:070c76ef1a14fcb79561f5298f336ac370f6db175302a7304ea8713f0ca5a864
Size
519.85 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:docker-agent-1-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:docker-agent-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:2597ec4a5c245d4dbce9a3751efae0bb07e68db067395fd9a37894600765a9dc |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:b3f80c08b2592134192fd683ae66ab346dab5fa45cb8f9c6be9922581f550172 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:7d90feb5a9ac7c27a1811114d8ca6544b3cc55ef9dc11eda5fe38adad62db2a2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:2df0c36b9056b5ea9b821f5fb8b4b691e545d376aeeb77af7d6e00e859b69fba |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:316cba7bd51f1bdb8ea8eaef0ef7a0cf4d6ea24039a0486ae2eb8927ef63d235 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:e6d63c782125fad676deb89a5dc0b5301ae19de38f34da91ee38055b98489084 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:2f1266a73124ae163193d4de7c844868993162d8de9c21ef20fe62ee09bc9f02 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:8ef792143a94f9def99aa8ebfed320394057154972f6ba9f0f1bafc8ef71cc6f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:ae950ae8a1fac223854b28a40870a96370d98b1835e0a76132102bc8c2e792a2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:c415e10b1fac435eee618461f9befa2ec88caab4466ceae496c9fd7304108de1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:b82173075ac9bc6b39b9e7c51e98120e6a405d065b033535ce977671dcd135f3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:f11acc9dcc8838be703c8c6ecba085ae43fca146b9ff957e9d2eb7b620012e6c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:09e537a1ac26020ccc014a7a664c5dc1fa3f2cb7cd3b07eb93c46db77e3f8005 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:124d688159c5b8c99ba6020c6c43787fdf9f1ee392ba117f897f1d7df4dd8668 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:697b802d173101ea64210606221823c3bb419aa7ac69fb8ba801e07ba434b91c |