Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (dev)

CIS
linux/amd64
debian 13
Tags:

droid, droid-0.237.0

Index digest:

sha256:c6b5eafc4f75fb0df6c1726896da90add2f881b5f17db26a825af816f09870bf

Manifest digest:

sha256:64dbb92c279945cf486c7734dbc00bc885568bea904d715b2dc4d0f6a445be50

Size

489.77 MB

Last pushed

2 hours ago

Vulnerabilities

3
19
11
43
9

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:f01511416d2f84bd726e5da00be49a6d76b661a71ee795be7b7445d0db79c3c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:65bbb8a8236bbd0e17e4d2ac0ba480bbb50ff3c616ec4331945650c3e8370a39
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:f6adfcb82de07bf03c3052199d48b38c2863fabf0b2753372fbbba9055c951c1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:05c53bb5701ccc0c765516f3f3a85ff9b5c91711e1bba9b853f9174395a6fdef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:85529a919da322120434e76c2245ad4127ff899dea0be4d4dff741f1e0c900e4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:65de2ce4f00c77ce822ddd300900897d89d8e282be76b762f7cf2ea7e7806594
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:a949c8a1de57f6b690523e51dcab3568b902fb8f36ea2c6fba97a98bccd2aa5a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:d6d5ac7058c728c3fa31232565b36d76a42c743e1cc4f99aeb09fc8ac189635d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:23cb7dbc5c88e825333f50f44491ad60bff21017e59a837cb615dd1066c99a61
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:e50fa11f58c5a4b8f3cbc935cd43100ee84033a855dda77bdb96e2c9d3d66444
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:b2d718a6bd64d2b0ae80aa6caf885fbc63c0b163d4350e21264d6016a5ae6264
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:31105348aef90b8bba11cbce0062a5d1edf67946cb0d21c0426fb98a24261471
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:24bece8403c8a896584d5bfb2971fcde25133cdbc1fbff5897fab4cfc53ea09b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:fbe9983d815ea86551e888f80d66a1bed5770e992212c227845d3f2445bbef3e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:6a2ad5cf38137705905c68227fcdbba7accf13d05a7dce202a653ede4c60f26d