Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Claude Code) (dev)

CIS
linux/amd64
debian 13
Tags:

claude-code, claude-code-2, claude-code-2.1, claude-code-2.1.295

Index digest:

sha256:bb721711897e0da455b2efb6693b74275d8569cc8d829e06431aa1c289c777cf

Manifest digest:

sha256:9427fcefd6b664f5b631137c0b3858cc8b56d34204bc71d6336f8f01a0201af6

Size

480.45 MB

Last pushed

2 hours ago

Vulnerabilities

0
7
10
43
17

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:claude-code

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:claude-code --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:e1f23502ce35f14e884bd53f08d6ef58671057eb0cf96534c8f2dd65d0f785d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:3894b447c507297f5d110a7282ed7e5f650d655e892f400cebe3cc3f2dc38222
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:a30a8479f33f3445e97e6ec55009f3f93f3d97548f6b8ece7fdb7749e3a7cd2b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:c01ebfa5a80ad0549203685ba0dbfdfc6af99ff799a1ae92b7ab878274236fec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:e203c76db6f0d5b6b5c56e3b1086795f1ea47c70f00a6d289cd4b4669498bfa5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:45e005828ab472f236d8d0a56084adf16bc6cb90446b63270ede746021b9d249
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:af575f37117e70c3f51ab850c14a3a71842f84665f6d2b98057abbe0eb619b45
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:300172887df92741a6268357236e4cb74ce68dda64dbefdcfe04099e8913afdb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:dfa5e4bda5fe50b6cf9233454bc0e7d62d7bd4298b9799243d19c3b49e1428fc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:b092bb428b5ee70684454441a49b228bfb93d4004e5a782d58390cc85a0e0c83
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:0c95ed7ff3e57930b770a4a1d0f8ad495b5dd8b01261f7a347d88277c326022c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:f3139642f85989f072aabe81114ef5cbd6d709b3b8bbf3c7fc35f81b3219bfe1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:9e274de92f3d308b899d5ba6c65ccf943f19088bb6a57a7b57df895d0dfa77a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:68d6c86d8eb10947e253a7998d491b54e778e71fa4ac18c3b1efe3740ebfdae5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:ad22ac742da68fe114fa85ddb0d69d78d815194df4f2bf95ec92891229ed71ef