Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Gemini) (dev)

CIS
linux/amd64
debian 13
Tags:

gemini, gemini-0, gemini-0.59, gemini-0.59.0

Index digest:

sha256:64243537be3307a9651fa8599edd85de75788d19d1ed3483c6c3b0c9d1f511d3

Manifest digest:

sha256:ab4e0c5106ccaa36b467824b7e4ecbb8ba9dd149a0d06f9e439436d47e7031c1

Size

400.34 MB

Last pushed

43 minutes ago

Vulnerabilities

0
1
1
40
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:gemini

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:gemini --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:84ad31228ec91d656c7e15f4102275449304ef5f6b6d31fc4af7be9b7c545c62
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:0c614eafb5af0a89d5acb2a7ad9cd4b5de5cd0278e2aefefb989d41f04a03e65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:fc8f41445588f062c99308485b3be5150e1df9370730d4e2120e42476be83769
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:a45ca3a784256b3c620ff12a98947abd8aa17af66aba4c750037b3a656773e06
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:1d9874a91e1d542ff68da2e6dd772aed7d24f82d9374a757e81240358697114a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:c0707e155ea0585065ede7334da10afaff158a9b51dd0d336ac45f644bc0c40c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:c1ac93d7232a85b0417b0c776db50e68bf300a784be3bef303c8bc109acf1b43
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:f56512cdf765490bed6c9f2cfbc6c3a59d5001b6173eb813eb6e17e00616436f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:9da33e5593f209392b9fe60b9d9b2998f2f399bd4dd893183f76ba00939c3c9b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:d17c9b0a2500c3970534af34d8df2d202e91e0434ee8c9d2696a7500b86ad654
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:d2dcd0e1f3126f39d241f7eb34b5bb863d193ca5f880e35dd4bbff55ab442a49
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:5bafb8668c406cbc1ee1df99f8c77e4f015ec1d9c6056302ecc98c85520caed8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:5b36725117882c180c787820d0a5937d4aa514edf05ce48c56a92c9140e8fe4a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:4b8a8349f4d36c71c2cdac2d21f9c479d5b5a4a1d1b4800ca3d7336b0771bf0d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:5d2fc9fcd0c3edd09079ba56ba756f0776d728bf7eebe2f4cfb0438a11ab33e2