Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Kiro) (dev)

CIS
linux/amd64
debian 13
Tags:

kiro, kiro-2, kiro-2.28, kiro-2.28.0

Index digest:

sha256:946b2d19a1b5db18d3b5599f1fb4865f8ca9187a6c663a5fdc2eba972927a045

Manifest digest:

sha256:ee98eb0bdb5a43c6577dd646c031b380c6abe7de5989dca3794be0050e24d5d9

Size

526.59 MB

Last pushed

11 hours ago

Vulnerabilities

0
7
10
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:kiro

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:kiro --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:89e3eea6012afe0f2376f136352be174333aa1c58d387c9e6771784277d7138d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:cd8c67736f0a44da6c725edd0e59358216a1b89ab818b22a7c5d9e310b294e2a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:3b9f582998382fdc4efb03fb03d2df18d3102640b94a22b9613088fe0e772f99
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:555d99dc0784173280c814242ad204a8b5d3876e2db2e2de17c50b12c9708a93
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:b17252d8954ef539cb272a99ae423c8a5b3610186d20c9f73ad3f9e75b739aa4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:818d702a2c899fc0288d5afb8afa0db7e9babbe4ab2869b44b0e5a85e0c7897f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:72a0a699fe68bdaf6725f182e634791527803f52aa761d71d9fd68fae7cf1fdb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:eb9c521bef0451e9712b82086c0d1036dfaf1b911d3a933b3ff679e8c70ff7cb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:348412bc56bc4ebcef4e101e26cc67be75e0c6ec6a790a3307566e15e3cc40b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:91348d4f2acae2f0b68dce941d0f3daf6ad1c7c2e5d67a19c24c36cf55cc203a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:84d53ba081d6278842dbbdbaef76a4c1c8e4348d5eb83ce6d1e4ef8d56ddc052
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:02bfcbcd5c3b783b13884c98f3f04f820623ca8f586830fd627b8549660092c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:4141fe13fdab105930322f36502157050826f2aa1df013ad913d6530b4ba5b60
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:eb07b27d5b947108d73fa949ff8520cfe73c5a33d6681e9b42e3c597b7b025ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:80809bb10891ae2348ccc86d572078002477301b542aa299bdb51a92fa6ac8e6