Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Claude Code) (dev)

CIS
linux/amd64
debian 13
Tags:

claude-code, claude-code-2, claude-code-2.1, claude-code-2.1.294

Index digest:

sha256:1b932a2198d4b6bcd156d9aed16017694df85eed0052a7f1c0e2549b7dee2115

Manifest digest:

sha256:b4cf70725997e363b0dc99dad78204a5fa3caedd96a0797b61126b743463dc18

Size

480.50 MB

Last pushed

3 hours ago

Vulnerabilities

0
7
10
43
17

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:claude-code

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:claude-code --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:6c6052e67d2c1d8d8590b25406b56c5affc3404717e1c9b1b8c9baa1a852fe6f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:615f1663194e7db90c5a5776993251a8f942f1cc7435e37d60df9ca87c57baec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:ae7321ba399c4e64bc656b0d59b515abd0711e1dd5c8c18020adc18e95df986a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:a83779375dc637508dfd094ae78ac4bb43dd7102b6de7f1f4cbfa993b87bf3f9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:fe304d35f7a4fd5c7ed1bfd3894d24c5eb9dabb200fd3310aa70be21ed388b1d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:515099b2fcb4f5692324b1ec82b03bee360d389e789ab947eb6dc6c3cadc338b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:36fcc156b6b06b6296c195409c7e3d0ab58e99a69ca55d393330f40524196aec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:3ac75c63ef72429f400141cfef708482d067465c5ed063bf831b6132219b2f90
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:23f8c2e724ad4ba55b9d7cc7599a2111609f8def592223360bf315a4aa2e5cbd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:c720dd81d5a41413b86c2e64005a5f4e6f4c2555cd652e17c4acb6924a8e185f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:aaa461d207fa85d558c47fcc4173996deb3a59da3a3c9390dc6273329031101c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:1b1616929cec51b1a1d7f6fc68e955bfa5ac4458e55a92c696a169ef010472ef
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:81e10f9dfdc241064fd771167b634083fc09700a3254034ad0ac197be76b2583
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:cce7be1102118a69f9fc10d2b9cc0a47f8d524bac2f22dfa19d3bcaaaf64b42c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:18f30ccc60e548bd88b92f51998150e823ecbda45ee8063643ebb82239aaf621