Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Gemini) (dev)

CIS
linux/amd64
debian 13
Tags:

gemini, gemini-0, gemini-0.60, gemini-0.60.0

Index digest:

sha256:008e241a8cc54809c2a3619424a2ff01e20c631d8a8ca7d5602d303dc4832b21

Manifest digest:

sha256:3449d45b06ed2c7ba2b95a635d0ac41f8adac4be509e0a7973f6ae040c4f6f54

Size

401.47 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
2
40
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:gemini

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:gemini --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:98a094d6cd342e3557fd67a05b21f6019f100bd0b170454e0cf8f59ad7a07ef4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:f80c1b1e161f9f6ac64c22b800743397e41e78f740275108d28753bfd5391522
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:1ede0320c4656415df920fda78b82c13b653a05f5d7fb80c5d1ab6b91606aec0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:93c630ced3dba55af0ec45ab4d9045419ea717a953801019cd3738d3a5b78ebc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:550bd95d6adcf88b8fee0959071ab076be0069b7e0b1662c549593cc66a168d0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:c9395cba6561d87cabf12da04181a90ea3ac87c25d2ae1a7bf1ad21322519843
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:b9a6298276b2ae157186aa07f08218666468eae2b63387905bfc12b17d34f17d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:6c3eb23927de268121664e7633d89836e6f8085da63d0121fce3ccd727191434
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:e607174111d7921cbe90d66ecd603a152185c2ac3467a9db1fb25e1cff03053e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:b5db79767ba1f48f5b2d2b87bc0a605dc28c92505fdba401c911a79090db88c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:031c3557c0a4e65e96e0b68f8d90c37c39f1e9b5ec052df288cda02636d66e47
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:d9512abbb8e3296468cfa0c25cada7950a878a0ca43bac23ed519f0544e83735
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:29cb6c0217cc84f0f11865ce65187413d851af8ff2b023c7826535d404c8db1f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:2d5d1114f2daca04c838e56f2709c93664f13cb2714b4077566f9a153037aa2f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:3e26f095355ef32df1e64eb69f689609dac904298a8ae3accdad0e12b65a0ba3