Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

droid-0.237.0-docker, droid-docker

Index digest:

sha256:39ea5dd4971c684f285c5eb9f0f969352da095ef1c56cf6a35c57b7a56141ad6

Manifest digest:

sha256:d54fa6da1e4a8093c92ba1893898389e65b6b02039c449f6329e68edab6626a2

Size

591.69 MB

Last pushed

12 hours ago

Vulnerabilities

4
22
14
43
8

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid-0.237.0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid-0.237.0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:1567b6656375c24cb45aeef66e2e9011aef79de4f1f26fef79ad9d72595c6110
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:a4e9d4e87aec8359675e8ce8160b10d43ef777d832f12587c9180b199accfa4b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:eaa886335e4105305f10e2acc5cf7af8edd58f7721e8111c1a04a735cc120a7d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:4e78be9fedbdbc0fb7b82dc083baac76ef936f3e391305f88172236c85b5b3cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:ffb4457db1af73cef6d693129772f23d54dba9848fbf59d57907318c1ee5769c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:c8aef42aadd477344149c056ddcd0bacaf94c5b514ee61e195dbc598dc9b52ce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:6bab1144438b5c8ad32d42f6324256ea13677198c84c5ab1677627578368e3ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:930d23abdad0cd1f115fb50782a5a34ac2770959a57c2c425d7b8f01a6588daa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:0947b095653e5f6abfab4cbbacc7c74956e699f3e386ac2b3d0f34e352605f6f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:ce0b4f8a348160262ebcd6452347a8abd39cd232a8bcd83a6c67d2318525ce98
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:fddf56c7940b4f56030dde6ab2e7af370f70faaf8d6c1f6402127a537305f7cd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:fd0a5879f45a3d2c1226b2e1aee1f068db6c2ca439e5ee756e69944171ed8977
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:c558e140e2f1bff29d24546a0882e1fa60e791cf6889dd681d30c4ecf8395a62
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:2853e13553f9dbb6a684ed5e929ce84920b09cea1898e7d2e4a574304081e042
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:0753e2786b92370ab8d626385667915e401b4c46b890a8c634c3005489f8ed5a