Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Droid) (dev)

CIS
linux/amd64
debian 13
Tags:

droid, droid-0.225.1

Index digest:

sha256:76fd2c4a9e9a4f4bd61dac6c67a65e3a22b520f1da8d3bf2a0097acb3e898ec8

Manifest digest:

sha256:2b2e1823c8cec7b6537c6acec495d9f8a545449fe2c43d0b1edec213d81fe7a7

Size

482.57 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
41
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:droid

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:droid --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:b471b4b140906a68b133352168f533e772e63ca6630dad58731e0d786a6d8085
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:ed7a8799b3d058016a038312d540ab6104672e667e69a1818bb94b2edb126d24
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:eab7507f3ced5c7beb4844efc93038ea26595f1f3b0670ff7fb2e0faf6b6e9d1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:5405f8fe97af6c1724de5bae16481f8665c672d247829858b9e6a280e97f3759
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:abb0dfac489e95ec927a0f523fa33d05150ceddc4b3157ae1c9e68d188f4d83b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:b7f17f76c6c27f184a416c2de0d5eb9c22d94e1275689a3db9d6666d37fa08e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:1f0be876cab5d1d7ad3f2221703e82ae466a0b408d29f17f64df8a1fb413d28b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:50e53c4f8fcc9af75abe2bc65b0b9589f05df03343367f7b64070fd069583c63
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:ec5efec6e0c360678077ca24cf02fe52fb40c7ad95817db378762e3a6ac2e2c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:61f99aace12cf309546be4e5195f3bf9b6c4f843aab349c08850ff478a5880c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:707c47c9af180df8a5879a708c64d30a81011503c704006804fca974b65e216b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:b9fb0788830ae096ce52b817e89cc87eeb4bc429a396f490af4f9ca29179ba46
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:5c42935d7d619bbc9f8578622cf4b16eaed73f790cc70f3aa0341dbdea029091
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:a4d2730743b8b732760197cfee080c0d67c38ff63d184245ddc4da6e6738c362
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:fa2966d2394069d93f603509bab0beae5fd5dbc868a99c237ca28a3eaabdf6f3