Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (dev)

CIS
linux/amd64
debian 13
Tags:

droid, droid-0.236.0

Index digest:

sha256:b6fa98ef50a1c9cf3fdd7c7fa1af5c3a0b862a0ae9079c129984812eb91b3f5e

Manifest digest:

sha256:b88805f58a0ba36ef0866fbec7b9c8c8dd345ef617e4a5caf4ffdd3f54c9d2e5

Size

491.86 MB

Last pushed

15 hours ago

Vulnerabilities

0
7
10
43
17

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:ba2bad1a624bab9d65a9de7da756aecd72a2eb7de107d3ac6e1b63c28024b5d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:63653c5e64ef7688e86e3ff3c0675476a0e854a4827a9f80772174a2e595d34c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:54a738d42a7b6bab8d27fec275ab7dc1d76d221bda95dd575f06cbf32c024b18
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:e0a59dda0186efee3df96e8558af250066036999623705c8e71ee23035146277
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:4f1ec6c2dd80900324667dbd6c300bb0e5f378280ac1bf6a29adb5494548db61
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:cecd5159d3bbdd9ce25ac767b4713e2a45eb96924e0534d8f18fa072fa274736
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:67069e97e9e9eaf042a6dcf97aeb477e55e05c30bcedfd86ade72c78ddffc181
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:7514d30b025c6e45894126fc00078434702cc2613327fbc6b591fd3b9e6a6be4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:c3630af6a6269809249423a04b0f78642ca1159a72a0890f378e823a6ffbd344
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:751aada59396698a3d1dde54ff255cd61d791ef68c9e75e401e001708c4e0840
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:250e8385b92739b0478bdab9a94f1b4142721a3931d6af6bf2a0c9a884595a94
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:9be2ad339a0c2daca8b86a56219a3ebb53eaa4097bd62361bf14856223ae0d13
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:8de14926d50d8f26aca49aef68a0569538254c4ca0864e3e0866954d6d583872
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:3f0b1d644a15b0d45f3a711310ea19e050fcdc29d9b9f0894e0352ac8feb3ab0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:32b53c99ea8d0bdcde35c93d40f3aae8c92db5f4b5ca9e3628967dc367132b86