Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Gemini) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

gemini-0-docker, gemini-0.62-docker, gemini-0.62.0-docker, gemini-docker

Index digest:

sha256:d97210ee3797484037b378699a4f9625345d74f4c55de5f73ae8f73fa320c7b4

Manifest digest:

sha256:57046ebb6fa54f075263b8a4e8da6fc7262539d564304e7cd0af4772bbd7ddd9

Size

503.01 MB

Last pushed

21 hours ago

Vulnerabilities

0
9
14
44
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:gemini-0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:gemini-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:9c1ab0c46c0f2ea84d2c69c6e5f89b17d16d4e0233f93cae936c96576feac045
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:30e2d40f7ac79c3689f542bf2b9aad86613651c480acea300caa81eb94ac68e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:2eea370ebf3d5567ee1a964438a77b34bda69d714415ae69203f5c174d2a8549
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:9697ded9cacef969812b62e01a526efea70d0902104ea6a5be7f6b6b3f626072
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:39eabd70aed803323adbee983efb6464884722a1da71e486253bf266c4dc9c90
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:3418fc1787c77c967dac142bf38201adec02c3af0b50e0f1edb8a1dc0b7f95e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:b65b06c0396515539cc9b56951efaa571ab1d0c902d7876e063c046654a58d5b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:52a688c3beca0abaf0cec8c9786ecde892150536cea88af8b8d3d1466b8063ba
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:484248eaadd049ce3465611273dc5d9bcad7db05cafc6763df548157560cc4d1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:e78b67f05dfc90ba4ab94d8db65b776968592ef02699fe3a9ad2ac99bbbf5b8e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:38efe168d3a7e76ef7d51b248527e1b89906b0e810fd1d29d4000a908eebfb89
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:ae518ffd52bba80f29b8a656b29ac37ab011dbe556a68f3d93b45ef2d2a77f24
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:0ba0e0311cd3387a0cd1cd0fb3fbcf7d62c3b6e51b3975aa3ea46320e9db7b6c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:813a40174717655ea90af4bc15dd0cbbd495b4b360d40867410082b22cc5b391
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:a24afce5572cad22b8a421af1bf301f8f589620db78be037a89a57c22c0947d0