dhi.io/sbx-templates
gemini, gemini-0, gemini-0.60, gemini-0.60.0
sha256:008e241a8cc54809c2a3619424a2ff01e20c631d8a8ca7d5602d303dc4832b21
Manifest digest:sha256:3449d45b06ed2c7ba2b95a635d0ac41f8adac4be509e0a7973f6ae040c4f6f54
Size
401.47 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:gemini2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:gemini --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:98a094d6cd342e3557fd67a05b21f6019f100bd0b170454e0cf8f59ad7a07ef4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:f80c1b1e161f9f6ac64c22b800743397e41e78f740275108d28753bfd5391522 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:1ede0320c4656415df920fda78b82c13b653a05f5d7fb80c5d1ab6b91606aec0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:93c630ced3dba55af0ec45ab4d9045419ea717a953801019cd3738d3a5b78ebc |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:550bd95d6adcf88b8fee0959071ab076be0069b7e0b1662c549593cc66a168d0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:c9395cba6561d87cabf12da04181a90ea3ac87c25d2ae1a7bf1ad21322519843 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:b9a6298276b2ae157186aa07f08218666468eae2b63387905bfc12b17d34f17d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:6c3eb23927de268121664e7633d89836e6f8085da63d0121fce3ccd727191434 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:e607174111d7921cbe90d66ecd603a152185c2ac3467a9db1fb25e1cff03053e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:b5db79767ba1f48f5b2d2b87bc0a605dc28c92505fdba401c911a79090db88c2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:031c3557c0a4e65e96e0b68f8d90c37c39f1e9b5ec052df288cda02636d66e47 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:d9512abbb8e3296468cfa0c25cada7950a878a0ca43bac23ed519f0544e83735 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:29cb6c0217cc84f0f11865ce65187413d851af8ff2b023c7826535d404c8db1f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:2d5d1114f2daca04c838e56f2709c93664f13cb2714b4077566f9a153037aa2f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:3e26f095355ef32df1e64eb69f689609dac904298a8ae3accdad0e12b65a0ba3 |