Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Kiro) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

kiro-2-docker, kiro-2.29-docker, kiro-2.29.0-docker, kiro-docker

Index digest:

sha256:30dd35529d1dd8db812b728b6c9942d11b579ab8357700421a082356e80f33e0

Manifest digest:

sha256:b1e5f2102a6b76d0669f15ac549525a2bc4527f51cfe40599060ea8615c1b8fe

Size

627.28 MB

Last pushed

5 hours ago

Vulnerabilities

4
21
13
44
8

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:kiro-2-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:kiro-2-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:ab82473d897e21d7956ab25f96a9af3c2b35d187cdb2027073b158877e9b0fe9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:4c9db8795e54eb2d7ab78a68442fbe56f549b4053029175d3d1b48afa5a93aad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:377b1805a4a9c50ce47ffa64a72cc590100d1a058b91ca833ef3aff5b7d00f85
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:c936ee9dc74a50f4b04615675026c66fcc21481ff7d08bed85eb47943725ce2d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:fc2de03770a521ad95d1a15eea1bc3689e3905ea6440e1f0ec60c5aa400ed86a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:344d1ed86823b390f5b1bd0d6666887ad3aea1c9ed32fb2845040c8dd9e9f9f8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:99aed9aea1783f9c56f1a08185447816c7fbcdb5744887107168563303a01c0c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:3de4716fa462d4d321b6d8bd965e6580ef16070311363ab767708555a9318e43
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:63e17cf7ccad1ba6760f575d25c1f032026a234c39246f6393846b12df61aeca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:05a6c18155c0814012b873be51037e05d9aa28a88d55a9d72a7b917886c5722a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:4880b48c97999887387cff2c8528354762c651ab3cc1cd6db85aebdc8076c90d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:e0cda560ec119a8b8db8347a16ed54155e1d5121fe4fda1f960c1ae759376ec1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:b3408881d89d756cfc0ca2cea3c4f6f859fe13f8834603332cce61ef18a055df
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:a711d7b11e26df78c2224bbf2cd4c87389f7ab8db6336c63c7d4938841cfe767
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:925e62d0ac9bc96de3f0de9fb25175d1580b85cbdf73f8661f2b1431b2969ed5