Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Docker Agent) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

docker-agent-1-docker, docker-agent-1.141-docker, docker-agent-1.141.0-docker, docker-agent-docker

Index digest:

sha256:f1e202eca5e5f662afd411451b37945d8432a3887cc073b299d7feee9313b000

Manifest digest:

sha256:f4f3fd4550c6dad92c0a1cf08ff98019de17cf2211211e19ff902fa4ccdb5dc2

Size

518.01 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
6
41
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:docker-agent-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:docker-agent-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:c101719561c8f6900bcd88d79b96308f8da45b2207af146b2583b113dbdbcf39
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:b4f1cb93c26a744a52910f822c940a67cc5cdbbbcc0ef0972e8172b43adc276c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:9726c4bfd642f3e774504c602f1f23032096969a3eb6443103c211d9c8128cdf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:4390f6f0972e8e01f7d7a4950304bb66501053d94755e51d0110112865915092
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:bb1fee894722bb46aecc133a7ead607f9de4030b35eb8b751d8e26951d70512b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:a016994f917154da822ee0ed3bebda9b8fd02419cfb446c2bc31fd49a9680ce4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:127a17d71ec8a80061cf9b75365bf2057980f63944c994ce7f9be1d421cbf21e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:0454115a3b11f5cc94d81cfa1df39773fb09a135338c1e98db982d68b7aaab18
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:eb02fb64f26934a325e975b789eccde92668cd8c7690a41d63ca9ff2d5f533b4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:19c5057f0605b422f2d2a929a10865431d14a15a0ba5c886e6bd01f1981cb851
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:e62bfd228c3d9f76fa19097cdb8e259a146f2c24d49dd104ba87bdd4e2930dc4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:cdbd94fcc6336d322db8f49326242c6740b31a77207c30950aa60d9c4b083d7e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:5c84de1a30479d6f3414dc7c91481cc96c520026a76d0fe414070d8090e9e919
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:96cffee6e71d5ed1c5e8d71b6ed0113a65ed93c123284b70667c0964b965e5e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:71fc0c39f4428a316a1c4e5cefc2d7be3672d051c397ba9a703a72b46c52893a