Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Copilot) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

copilot-1-docker, copilot-1.0-docker, copilot-1.0.88-docker, copilot-docker

Index digest:

sha256:06aed86d3b5aff3a96ec0d6f02f4b1bd02fa5c7242b5b6f453c74827db282c7b

Manifest digest:

sha256:3fc34d3af4c6065c9d5df310f1c5314b7793f7936845ac2d339cf4a82a911f8e

Size

577.03 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
2
41
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:copilot-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:copilot-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:2adeed1f46f93af3e554fdc5c8510554fdb0f082ee886e8fd00fca17eedf0f33
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:5cd066d532128623f5c6c8f76466fbcbba2a65f30b5b558c56fbe047824c616f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:f052f54123215bbcc11cf7f56d3a1d42d28e47e4df16c1f225b5b68a32bf387a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:bf63988931c8498ced530cd2fe3631e37195957eb89156fea728903bd50b63de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:85dce9a39d4597f94fca519a25e4275f06fb897cade414a101ecbaec869049b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:0ef8393ad5199aa86735795f0e923adb983ff45414b0ad754a3877e16db9fe27
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:3cdc2ce71cdfb8266e240bfd64e32ee6c46da1e690097881a432ead033081c42
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:6b34fb902f6ac7a01716c3069df96b533164bb53551a345d0c74be75d38f783d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:cddfd1182fd876614b60c00d5ba0bfcd79482ca2ac5d7fe526fcebd137b2de55
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:4e4deaaabe7e71ee71c930079c72443149309447548199ebc1b1cbb3d736b7ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:5ed32aa4f4ec61b634fafa526eb17dd1793bd862ef2ab5d8dbe4da478916d019
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:6a2361b64bcc388f3c865a27b6dbb99869758e48f56279b1afa90e0817c0322b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:3bca6952755457fbc920f0910d3ddf5a47465ae554331893c5a8928cd4d90a07
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:ffc64e1a166f7dedd9c74117895cb5260fb733673d58259100f732f153819d90
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:f2c8dcef4355c84f125de59545a8b20835f94511f021289740d318af6bd95912