Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Kiro) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

kiro-2-docker, kiro-2.27-docker, kiro-2.27.1-docker, kiro-docker

Index digest:

sha256:8dfdb37a2124d7fe226e5a107a084885fd497f2b3390ed29dd52443775e8c5b3

Manifest digest:

sha256:175ce42622eb66532527e47df236392817a4db752ee344d00670a09a4ae766e5

Size

627.93 MB

Last pushed

3 hours ago

Vulnerabilities

0
9
13
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:kiro-2-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:kiro-2-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:f6b42721076b502931c1cd1c37b29a2a8628b450268c5a32c7157186f52829a7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:ddbe6f25b22ac17fee5e7f3c839015400045d458bd5b4af7bfdf529008cc9e93
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:a8c1a11dfc8b49c0f6bae0dddbce3ae70e12eb4b9fca1ff4637b947e36d50ef4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:b9f0158f5c352934163ba05d283c18fd899693e3911ba2223c744e46aaa91c52
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:010543e3dc68238acd5049b4024f6a24d2de28a00a66a5d04007007912447116
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:00e5c5d895a3231090aef336c5ac10883f623aa775b571a3c652fec6c9e321d0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:734db2e09581891630d8a0151d05b3e8cf448e034540df00e7233c6acf26b9b1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:272f5d46be1161cccb584dee5d25065a8e743ac116d00d49d199465805b1f508
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:8e87436d37df19b0661df7ba7260a6838c74bc3a2480ba7a5eaf54a684b85df5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:dcc533bcabc1b1d9e27ef2c8c1d47c0f5f69c91ab5d179999c26b732da173e11
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:a914d208362cb00f82c4d389516df1e0531bf71fd3e2327461f5cea27d465546
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:0924017f8461e385eabf9be8aee644b451d7b49d28637a4ff406df33aa9a14e3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:a902225a341e1ffc568a66b506103cc2c9ac3765bdda269bb856088675a50af6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:2986ab339f51cb4b87ad60ae57f25d3edfc56bd770a5ee0b4b8dfa203880d58e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:3a9d7db2585aeb9500bc855d063fefbcfa079d70da1dbce73476b79b5909cb6e