Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Shell) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

shell-docker

Index digest:

sha256:f3c1b9cdd87d104ed6999779fe3fd581df95dbce5d077602eda3b9dcd993d4d6

Manifest digest:

sha256:53710a8d519f6ac94b34936f9b162e614f457a52df35245ca37ff9c7ea220b07

Size

486.68 MB

Last pushed

12 hours ago

Vulnerabilities

0
2
4
40
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:shell-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:shell-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:4bdfced50ee459eb596b379dd0709faeb3e0f941325a35602ac6553212b0908e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:508cc21bdf73fb039b4b43853b4ca7eaf3b94a67d982050f44fa65435536b096
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:e6431b46f4ab01eb60ecc3f822e9866ebcef5a5c43ff96f4f33fc3d635cea817
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:7261470d861d91703d2f4e5073753b02153193ae5d2279c167f2d51811732738
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:c0fb965d21955534fd5fdacc016809da11165ef0525b1cb847c560fe2bc552bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:8470ddc33b2e4f1f0752e2747453c0121604fe860e13e9e99e0d368973ee065d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:f2ceebe2c05167aa324c5b35291875d71386d2673ad4c33fe6420fd5bc619a0b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:10a5870970c5f11e2dabc5b75e215eea422ec41dd7a447b2e92cf3a0c2b16c76
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:c1ce291cde416e37beddf24947aee425bf0b9d28bd0fcef6ae5b60ff37a65402
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:225bd2308d3393c406506cd3dbf8beff4d3c2394594954e5588f7d96e90c95cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:8527cedfb125d77201cae35ad0463856ff40749688d2b739b0de25941fb4cf40
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:f49d67e0b31f263004345d24f511684f31081ba1cd60208b17b50856ccaa2cd5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:96738407769361115ba8e1aa15570a1941fddc2ec661f87f55276366755ae1f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:a512d88d6b618faefd12de0c107a616152ab6c3f61be99ba24db2ee07730d6e2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:1cd900c99f7bb0f45f5c841cf0d53d06eab811fb12171c3056d57754c00c7097