dhi.io/sbx-templates
kiro-2-docker, kiro-2.21-docker, kiro-2.21.4-docker, kiro-docker
sha256:e3cd1336b61da88f127b2d0d679d7c0a5623ddfa83812614ac412159166b6882
Manifest digest:sha256:ccf8ce4ff6980cc3e9e32b5e827289ce5a23d71e2b2ccb820da8b7e478a60c06
Size
1.01 GB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:kiro-2-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:kiro-2-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:565743e0e436856f5444724ffc5da26b65154eefb7ec8c0a0ce9852ad8248668 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:a14488c6a6613e9bab215452604f60c8067f146936927a01919bdb7bb1896707 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:b677d70f5fea94d8fb9536556d9a3a806432f86f9ef7f672a0938774e9e54d9b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:6c94621f86b7010556d98c333ed3eb479a59e0e88b0495d599f1a0b4dd3f881b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:c70105e97168af4ca8084e0ce7f6892df675ef3b830da8ae85a8e6e005f25f71 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:b631c44c1ca4d56b514bcb08fb4795097319fea9c4aac53811c6b1f46171bd59 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:0488c5cf14a9ff03470b42bebc8321235160b76a0907588459f2b1f91a943508 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:38d86d6cd691309b3854d62ed90ff7534951d03453502962a34ddbc018af8927 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:2aa07b320ab6368bdd4ef858e7b0f23a428e0f31f37fad40fea765591a7eb6d6 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:b8ca13c4ac1a5eee4b766904da733856b1fb4ee5e918a969d58172ed654c3d5e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:61bb0f7afc4b47b2a7cb90748f8f5f0c1b5b47beb30fe033183e3fb12baff773 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:a3a3534b675934f59760f75eb0667100b6408e1540879fcc59871bec3c8c308d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:2b87c8c8839abd16637855057c9819108f3045bd345c040633fe5600fe6cfdf9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:54392b6f2ca541689c770226d6a68faaeb0aed637a5f350522f1986d5db2c47d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:210a6cff29fc98e1d554b1eaf26df1d99876e0a4b7b906e9bb9e586c10da8c51 |