Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Claude Code) (dev)

CIS
linux/amd64
debian 13
Tags:

claude-code, claude-code-2, claude-code-2.1, claude-code-2.1.289

Index digest:

sha256:adbfe17495796907e2fd317f5b679ca3a0718d95db155110a4368255209adda3

Manifest digest:

sha256:db1fc342207bbd15e98b5132ae117f40e05c1fca7746cb87fa4d401ef8b8d4dc

Size

477.05 MB

Last pushed

15 hours ago

Vulnerabilities

0
6
11
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:claude-code

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:claude-code --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:ac88a5315d1041922631a1b3906362f6dbec3fcb0b85ef831dab07e0bbafaa0a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:3017f05d535d38a00470d2d985c55eecbedb8bf878531271bcf2ddda95959fe1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:3f72aef72b1781e4383cba8ffe171da050a53c14ccd92bfc4300225da3e10bf1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:798c1e29393bf06be4283d4634931424ea195e79f59f38c75e9e4672be877bec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:1d84b5ce2f0d2ed7258700401cebbafd01c4bedae0354d8aa3d2c87d1235f0c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:c3dd578c422ad32130d9deb00084c06aad3df6a205e13d961d53d6a00336a4c6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:9c4d5e1d8bc41beba6c44650aad94b9104247c9d83a8ec8f5113728bfe5b1aeb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:0c898872af5a97eeb4fdc1bcb32e69374258def2d3923786fa93894d10815340
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:0dc3008d7bee704e6823c318923c66eda58a2731c0c4b7a69100ff060783b1a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:c2d0d86c84103dbc4abf172bd40309dbb1cd0dbbf6f59d82b13b8584f4383042
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:92143c7ea6f4cabc1e479dfa6fca87538eda668349b2d65947210410657230f8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:3abf002f517e5b4ab5631ab19d43e48e380074c8a5a018cb0f723c5981612d77
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:3a817a31cad710173a136abf4b49983679380662cf1a3bc332df71b8a904ea6e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:f6e235d9d49172d673f6bb4d592a701c94246626d0d11983d13f921a895358ad
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:6d2f4ec7ad9f5ee557ab089472d9bb5e0bf4fff053944edc450cc86301d1d6d5