Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Shell) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

shell-docker

Index digest:

sha256:4fd0061fba3decdb0f238ef5924717ff357c922a4c63666a90897a888dc4d310

Manifest digest:

sha256:26b470cac319a25fc84fbedb967d89899fb6309924cbb1abb95a62447075a805

Size

486.56 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
4
40
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:shell-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:shell-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:8d0470f50f0f6423ace2efa715c93cefcda9958bf08e7356f812e7b9d353a74b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:653397f1fc26ecd89b0f8938cc28cb6750b57bc3fe36c5aef4557a74bc533ed2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:2348ec6701c4f1cd81fa65711d2f0ea040f430aed7b90b56009be608d05ca384
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:b8d71e8851d3c4dbffee2c975d43d8c9a4105e84b5fb48ccd5545ea633a70413
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:7c2191838b4601b4f0a7b4137bcf8c09a51bcdb92170ae2355e465f78f63c697
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:ff33bd4e1622a2e37c97bcab223449522fb8f690d1faf592378bb6569f75c4ef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:eb46105d974175d059d0d254084ddeea15c42d78882ce4edda3cf401999aa831
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:884274063749fec76987f0e15779deaedf9766c52e1275a771cda5ca1b8365b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:bd5899adc1fa1335ca2f8bca2d816f88ebc90d3fdc77187b5da67e541fe66471
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:ca293a0d1f5339b042dce834bcf79e2a4db7b01fc335a2bbca12703bb89675af
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:7d8c830af7d7715e6d6043a8e93fe39cb38fba93e3ee5b4eb82b07f13ccb01cf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:9a3e9d066d38ff7cdd5c29e42a5e5489d52a18f95ba964cfa6ea6773f90e8d5f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:c7e81412dda7c06bf5a4ba0f88162e7b626b5fdf6692005d628c586133d76049
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:a6129ff28be9f7e233813ba42382e27e0827c89224cc7d430e5b913f80394d2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:74f8c6c3aac50cdcc3c327a447d41e15963afb466de8585390239d78bcfdb4cf