dhi.io/sbx-templates
copilot-1-docker, copilot-1.0-docker, copilot-1.0.88-docker, copilot-docker
sha256:06aed86d3b5aff3a96ec0d6f02f4b1bd02fa5c7242b5b6f453c74827db282c7b
Manifest digest:sha256:3fc34d3af4c6065c9d5df310f1c5314b7793f7936845ac2d339cf4a82a911f8e
Size
577.03 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:copilot-1-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:copilot-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:2adeed1f46f93af3e554fdc5c8510554fdb0f082ee886e8fd00fca17eedf0f33 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:5cd066d532128623f5c6c8f76466fbcbba2a65f30b5b558c56fbe047824c616f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:f052f54123215bbcc11cf7f56d3a1d42d28e47e4df16c1f225b5b68a32bf387a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:bf63988931c8498ced530cd2fe3631e37195957eb89156fea728903bd50b63de |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:85dce9a39d4597f94fca519a25e4275f06fb897cade414a101ecbaec869049b6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:0ef8393ad5199aa86735795f0e923adb983ff45414b0ad754a3877e16db9fe27 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:3cdc2ce71cdfb8266e240bfd64e32ee6c46da1e690097881a432ead033081c42 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:6b34fb902f6ac7a01716c3069df96b533164bb53551a345d0c74be75d38f783d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:cddfd1182fd876614b60c00d5ba0bfcd79482ca2ac5d7fe526fcebd137b2de55 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:4e4deaaabe7e71ee71c930079c72443149309447548199ebc1b1cbb3d736b7ad |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:5ed32aa4f4ec61b634fafa526eb17dd1793bd862ef2ab5d8dbe4da478916d019 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:6a2361b64bcc388f3c865a27b6dbb99869758e48f56279b1afa90e0817c0322b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:3bca6952755457fbc920f0910d3ddf5a47465ae554331893c5a8928cd4d90a07 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:ffc64e1a166f7dedd9c74117895cb5260fb733673d58259100f732f153819d90 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:f2c8dcef4355c84f125de59545a8b20835f94511f021289740d318af6bd95912 |