Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Codex) (dev)

CIS
linux/amd64
debian 13
Tags:

codex, codex-0, codex-0.160, codex-0.160.0

Index digest:

sha256:02eb509b9a6993e7840ad724ff69b5073aa3438bb5c0a30b104a07d00d83c838

Manifest digest:

sha256:c100f6756ba6f3c7668f19af663d0010effd63b94c092145359526311fb18b92

Size

512.09 MB

Last pushed

15 hours ago

Vulnerabilities

0
6
11
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:codex

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:codex --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:061affbe8e1af710e771e792a6f0cde44f0d4f3725e5efb100e157efe1f48a77
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:de8d63ff161653da2418c12d2442f869753060042874d5a1a19200be5b7372c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:3d9115e20c72bf04647131d586e6c70749bbf6609dfe4fc298dbe038d6cba0a6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:49e1ea10aa698c116d76b682d86cbe8cb663456d4dce5b27df756562d5bf4dcf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:1b0b7383c384778589fe14abeb4468b8669ace1e6854eb21e16b926a3c57a568
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:0256f64d3f96e60379cba193cabaf3ee096137674dac554e53d287684ac74aff
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:b1ab3ecab4e489a6ce79e14cb2781aec70048faf9e1a98269517feb320a14715
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:1a14c198c5390bb1598c4b66bb94d03ade602553dbef4494abb9dc3574a1ca6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:98a9d8bf66fc2ae39819c18f7d3d5d68f9a5fb21d6a14653f89dc33d938c948b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:dcccf1c25fb249cce6339cc92c9f855bd393c3805359a2e305560ef4f2f96c0d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:571bd659cc53545603f6240083fdd46c66ccdfcb4b5aee5d537b49cc091138f0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:4cf6c0ea4f0c59f6ba6fa6d849cbde0e68ae9bc141824ad0b5dd4b2b31e65e0a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:32d09d2b20f9d49570c358756b3fcc1c9fa7408b05bbadf9270faa1660668bb1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:a6a76d7d50e41a1310179745de8c3d1fc5623a99c99dc0b70c54099af8a2a007
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:10f3df574156ebef78d4b2cf56e851aae1dba06c687f1baf39e1c1abdc6e4642