Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Gemini) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

gemini-0-docker, gemini-0.63-docker, gemini-0.63.0-docker, gemini-docker

Index digest:

sha256:b67f8742a8b90b6acb38d6515a5754b34e76f481cf51ea254a803c73d091aeaa

Manifest digest:

sha256:b5e1b49bf5cd59705d59739b6d180b245946a6ff8490f0a79e91d869d6e536e7

Size

503.65 MB

Last pushed

14 hours ago

Vulnerabilities

3
22
14
43
9

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:gemini-0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:gemini-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:e8a46c89b37620468fdb5014f313a5bcf359c04bd8d43507f2adf484453b39e8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:c5c44c73e3b24ce9f425df21b761f0e899ff709a1f032573293804c43497f239
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:c79fc802fd6bfdd7fe60237bada31aa6cd8e6ae29f27004524a89b06511a943b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:37bc5e022639033d6a1630320ff5c3885bf7ecb29032670bfbdc4c4952ba712f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:87e7740b7e74bafbf2c92401fba613c271c23f3ee4a13ef655f48b1998024763
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:5cb5ad556fbdbe9d50ec4fd1ff2f664505e939a619436f4841da83435b93faac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:8f7c8b487523e6ddfd6a368560837ff996cfd743ca56842e2d25e7c52e977321
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:e1a50aae180b3db7c67dd05066ee19c686eacfc690043aa37d9e532767d0bf18
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:6435bda96298966ac73e9ef629b3c7b01e99fa677a65871daad0b6790be37ed3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:cbcb47071f6f5793802e6269d9d0083b14bddc21275f281e0f48604cc6d39ecb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:278cf4de18c4bc6a4a0c55a853a95e72eec45b44d9f5baaa9118742e09dbae6e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:4036c106b85280167af685789267503b7a2c2b1f60ea854928f3e0a8ef1eb5b0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:9d73c563db5b7b7fdbdc000ec2df0cff02ee89dcd67622241a261741bfa62394
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:00b6507a2985a188d467fa3037058bbfe1b3731c91df01d79583a9dd6a39a8da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:969ff5d676d6638ab2b3aa7925a19bd1bb20b1de6a60415c69e64a28238b68da