dhi.io/sbx-templates
shell
sha256:7fa81ebcbb86c5882b60d5d7c7e2ce6ffe1478e762bdd1009505014fe832f765
Manifest digest:sha256:012103e3e5125e30bf6491bbd0c359c8574e8b391ce3cf4f8d5dcb71b0cf089b
Size
385.55 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:shell2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:shell --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:7c0bdeca184f0acd0e7eb64568ff4325b507ac4184fe79b3c67fda97e4171367 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:340ecbd63c040a5cd4d3bd0e11c74dce2e7f07cde34d91f41e25fc6ad9691dde |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:1c4c24d236d5405f3bf2bb3828ca6bf9b53b86ce43a42df9ac951ade8cf38d21 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:fd6d75ddaa88de034f601fd8665579cd797f189be7493ad5dc47690325d7f151 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:26b48325baec69b2585c596f6d5e94b7cffe1705ef8b9740456c8315b5b5e359 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:b28186655af18c7d899bd2ce83b615e30d6121d40f7025684c3c66b0e215c1af |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:0cf8ffc196d0cc85203272fb856a2579ede82543785ddcd917ae6e52dce6569c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:ba79a46f2269647ea8104343088a43509e881e1875833562b2aa60f3d6ee3d1f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:96201583225d389e88109fbb62d4979f44f2ec2878a32db72df79c66d789336b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:f25be3c5f6ec4a815906a994e9ee7096d3d8bf875ab457c14e8b452e44f8dda5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:1261a4dd8c7831473118a27fc9437aab8e20a50a8dd0d3ad17f6b4b03a8b765b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:3e769ee329765c71d7e552727be584575059efb4ddb6b2fa49e66804ab5c9cbf |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:1af655591b82d68d8486ac089b1729dc07185dd513d9680d775ed51a7eab9dd0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:9571d20df9e73ad354719409a4a34a80f7545de634bec931acd88fe5fc1d40bc |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:bcb8968e85082e0a1e86be9f62c4039f1554aa0f7e0b0d77313508d4e4b4c610 |