Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Claude Code) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

claude-code-2-docker, claude-code-2.1-docker, claude-code-2.1.291-docker, claude-code-docker

Index digest:

sha256:227017082d7b0e743e130befadd75735f672be530d6f0892ae67a31710cdcdd9

Manifest digest:

sha256:6ebc5c753730e9cdef275b74eca8a7b63ecce761c2b41c456f35ca1af9f8f8d0

Size

579.61 MB

Last pushed

13 hours ago

Vulnerabilities

0
9
14
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:claude-code-2-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:claude-code-2-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:95dcd54f7c27364385172c13672cc888a34ca806c52dae2a089b86aec54ff815
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:4501b5fe387e5edc2681357e5521806b0dac064eb986d81d89da9433f4638461
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:386ebcb9204ce3aaf49cf1c76745333add9c9906ae089af2deee66ef8645cea8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:62d3f2a68922be96a4086ec854268418df4fb06f755ffe48d7b968111579dd20
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:1c1715ad0d4a419fc320f6638e7282a1a3ac4f41cd3b9888d37d3b22ce84e265
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:856d65d0799ac5ec5da85e9a6ed11e0dd6708dd549b2d8e4a6d2e82116f77c2a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:9560f9e46eb5dba2d1f373c45822af6f725b2c21f3e8cbe8bce200fb4ec09df5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:f7c11608fa241150f04fa90b5c20f5b827faa09f8dd9b91ccdbdde41ae7182a5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:91179a514900d556e24058c74d15a815a145a6cda24f03ecb4882cea6e044990
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:a0b3f46e5105bd27e9ee60ca26c47e49114051d8fb3c43e990587c164c5733d4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:c5539ca73ebbab02793c633daec1943be3d8e20ad778d18c84c61b1ae48f0ff7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:1f0fd07b71e63e98ac75a5c6edde2b28ff95f6e0e01bc193e19fbaff8d58926d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:906468e56216ab468c982641b252b9f9fd7fe053d94d7635a03ba6657a875859
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:b910ad6cab5433ec603c76400709c0ba48d0715abcecd23fe319d404b28d4b29
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:e6b7e1f6d7d4d5af5b6af08014367ac2a72c4635907cc66c82675185271144ee