Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Claude Code) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

claude-code-2-docker, claude-code-2.1-docker, claude-code-2.1.292-docker, claude-code-docker

Index digest:

sha256:52897554929df9f41649453ff3b559d5e87fc295e59e737de55b208589d6389c

Manifest digest:

sha256:ee863dbc88cc6cb04aa8f4544a1e7adb172b09900b9dc6387f70e77b8efe5b88

Size

580.27 MB

Last pushed

9 hours ago

Vulnerabilities

0
9
14
50
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:claude-code-2-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:claude-code-2-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:598ffb8cc2e697e59f2f07eff8beff28d0ee7dc6cbe6d7bd53f48697a0740f3f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:9c3bbeeab571b32272713095f7a335167afa9ae7162915b35269f0b6e16b7c09
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:e59a9ebeae7d0dd4a47c9c81b7706fb8842a731c7b57960b2242a9ca64f47fdc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:8548195f563e5bff1aa2e387ae47c08bad0de7c42f52a168d842c9601a7af005
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:b89ee3c0fe0d1925ffa1949774acb1c3fc60ccbdeee2f6baefbfea46679c55cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:eca29a9f577439181f37486709b8adcfcaaa08683837547219dd29ea90fce96a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:206fb81d3d72b95b203870d27570076cb85ee384b4757e92016a188c3fbc97bf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:8c5fabe0e4e2e49ed0081e9de3a6e061643df7e969b19656eadaf0430746371f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:2d1a989aaac01d449a0d86ca652a680e11f5ef75c030f8bd6ff024db5ad2685b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:7fc8f49588a4ff7584de98b516941cf956240daf1a8b1b6aac74f89a42ad6a6b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:bb3586bea86bdd8cf4882c661153ff16b44deb9da0c09a186969a409fab0b706
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:011ee370532e40c13c70124ee0c3c5191ca4ee9750e98a887d65bff4384124e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:c7a4e9f602443528c15addfb91f9f1cb1cd907e360899b855938f6439b24f462
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:4e0ab986d92c51889a607a18ca5c2973e4d296de96a1ecf0c4a775cdfd9a903e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:2e1552592db68089d195f9e0bf129f52ef8205fd98093a9e0b80fbe364cf8d1c