Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Claude Code) (dev)

CIS
linux/amd64
debian 13
Tags:

claude-code, claude-code-2, claude-code-2.1, claude-code-2.1.296

Index digest:

sha256:4f3ca06dcf33114a289fc5b5ec39f1d39e41f4b7c5af64cdd1e963589092172e

Manifest digest:

sha256:716ae38317af6adcd53081bf49af7e9cb58ccc8452abc35282a1e98f1b703231

Size

478.86 MB

Last pushed

10 hours ago

Vulnerabilities

3
13
10
44
6

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:claude-code

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:claude-code --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:3b9ee36acb7f13f9bc3967ca6b731653fc04529966503779f2368acae9b26eb4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:73a57b119d60f70aa39dff7396aad8bd53823f8f463a875ae0e25349fb214fed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:c1f0b32dd9ecb222ae2d7ace0066f1ff6128e1f5e3108173947e5145f694abf8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:53a5672d91cd3ab63579d7afbf869d7e7b012b3ce8e9dd9622beedde5756c1aa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:214a8f339ef9248623932787c2e57d02ea99d7c781de6e88ee17e99e17d3dea0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:bd52295e45ef62c03ba14facb913cea49a56cd5bc69c7d188decf9ef589b98a1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:b23601bdb2709544c097cf818fd06aff9a1e3795b4cf4e0caa2a39b1e3482745
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:17aeb74119719dff739af649a41ce9039b665a48893cc006da31c74eace2d8ab
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:13411c66feb94c1c76c90742557109010481eab23429dacd9fe5c492fefc367d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:d5a7995f628ec74e307b8c7199d21e57714ca1a4c6cbf9539c420338a462713a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:b20bd10c49bc27ef72417be7fc2c31cef2e2a95c206e3177a2e0ae9574a6b63b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:2f2ecd2dddd7b9d6db52372ff97238c7d9755645f646c28890ea05b2a3958e32
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:7f4642d1eac37586511681e8b42bd1c816ff479c1eb9b298e1618f286e350fed
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:3d57edc6dd380820b9b2c932911d0757e4b913f01e0ded3772af73f647f3d9e6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:a42b453a8a1aa917ad2768b3dd1b39cb3b9781c3ced29efece76e05c283f3e5f