Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Shell) (dev)

CIS
linux/amd64
debian 13
Tags:

shell

Index digest:

sha256:7fa81ebcbb86c5882b60d5d7c7e2ce6ffe1478e762bdd1009505014fe832f765

Manifest digest:

sha256:012103e3e5125e30bf6491bbd0c359c8574e8b391ce3cf4f8d5dcb71b0cf089b

Size

385.55 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
41
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:shell

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:shell --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:7c0bdeca184f0acd0e7eb64568ff4325b507ac4184fe79b3c67fda97e4171367
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:340ecbd63c040a5cd4d3bd0e11c74dce2e7f07cde34d91f41e25fc6ad9691dde
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:1c4c24d236d5405f3bf2bb3828ca6bf9b53b86ce43a42df9ac951ade8cf38d21
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:fd6d75ddaa88de034f601fd8665579cd797f189be7493ad5dc47690325d7f151
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:26b48325baec69b2585c596f6d5e94b7cffe1705ef8b9740456c8315b5b5e359
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:b28186655af18c7d899bd2ce83b615e30d6121d40f7025684c3c66b0e215c1af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:0cf8ffc196d0cc85203272fb856a2579ede82543785ddcd917ae6e52dce6569c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:ba79a46f2269647ea8104343088a43509e881e1875833562b2aa60f3d6ee3d1f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:96201583225d389e88109fbb62d4979f44f2ec2878a32db72df79c66d789336b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:f25be3c5f6ec4a815906a994e9ee7096d3d8bf875ab457c14e8b452e44f8dda5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:1261a4dd8c7831473118a27fc9437aab8e20a50a8dd0d3ad17f6b4b03a8b765b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:3e769ee329765c71d7e552727be584575059efb4ddb6b2fa49e66804ab5c9cbf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:1af655591b82d68d8486ac089b1729dc07185dd513d9680d775ed51a7eab9dd0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:9571d20df9e73ad354719409a4a34a80f7545de634bec931acd88fe5fc1d40bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:bcb8968e85082e0a1e86be9f62c4039f1554aa0f7e0b0d77313508d4e4b4c610