Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Codex) (dev)

CIS
linux/amd64
debian 13
Tags:

codex, codex-0, codex-0.162, codex-0.162.0

Index digest:

sha256:6e6a5f306d2663dcbdda02d608379628a55a38b9aef1d15a369dc325ef0cc5d6

Manifest digest:

sha256:65100741dc57b06093aeeb5f29d24fed9c58982dc68270f5594ca17f4c11f006

Size

511.98 MB

Last pushed

11 hours ago

Vulnerabilities

3
13
10
44
6

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:codex

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:codex --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:2d667373189bae599d0dd98e49c8f1adae1078a458e48af6cb22c6cbc082df7e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:89c4caba1fc4346944c2bd07e9007e84b99208cf420c855250db998289cea7a8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:26b07bff5adf9ffb77a10fd876f6c3fedff2b19af696e80d025fb69b47750f6b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:048b0ea3ee5f2f082f6551425e1f6eed0f53b8b2d1efefec75bbf3149e92e651
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:cff8c7fca94163ec4b54422711034209919b2c4066db77ffd0e26faf3069a634
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:38de77eacba05795784e7c9b0309b98361d9012446ed3a723ae42f2679cb63e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:a8bce9a49cbb7dda29d3597882e2c37563f4f75577b3beb1c833608240cf88de
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:cc02640ec8ab9a64740c510de7aafb9a9ea597eae3a0635879a39f4bb77c7154
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:43afa2d4dc133f778995cd6e072060e2c56aa04d3c9959bddb142186d09a9382
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:6722fe054bcf95c05e133f2dfd4b40a0349efdd43a0576866bbb4dd25ac26b58
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:8e88380db73e3ae6ef988b64a6f8e590c499ab582a4aa6c6ae8c43596bbe8458
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:27622b9ee11bcf5e3a2e5eb29487425970e793ddaf8dfb2965a8ced1f429c244
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:5e5da742506c0b2196f237492147d185b140f6ab6a8c55004477deaac7c10b0e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:72dc9b78d9087bf6dc439cc19255afa6f35d5cb5c705a4ab702bb082cafd195d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:9bd002adce4bc3d814c1a6d4414238e671b363170d7202f12b10693fa1cb90a0