dhi.io/sbx-templates
codex-0-docker, codex-0.160-docker, codex-0.160.1-docker, codex-docker
sha256:802c5dff842eb0c52c210613d851e89b7b492f3031e5fa10823515b9ea25e49f
Manifest digest:sha256:759d44aec80905ba2c92641be8edeb99cd1fc6c3d60c4d05e63f7610af195955
Size
613.48 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:codex-0-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:3ea5937e36a39b5ae78abe635f3d9a5fed2041e6e21544d5800c6b113fc03f6f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:ca0f85ecf178743f823cb0875cda4477d7a6f4cbe12c9776797645ff0b1969c4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:20d0b4027d72a4488d21b94ae522d4893aac4521928181b4cd16d695838433a1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:8e91036e1173be56e7ceb45e28d6b083eaba5e98242794222673eff1b9c9af27 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:fb12d16a5b4c71f92b26bde62f4a28021768c77f3f12836af97a9079443aad38 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:168d8be4d33b72c572ba2f8df4c72e7c02c981656433ec0d2598295d7e92e4c9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:c44f864a875906da632f9fabeaa7d31e37ecb33881c493b30018a872cecf7177 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:e9075c7846fea2487878102eed12f23b172f88ea545aaa9638e9fd8586034962 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:b0830d69701bcb7e4b557e272ea419002704abceab509740fddbebc7c258638a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:a45f524a4d228b851b0b99f1337009c31453f5e0280aba914f0e0e2030dfe3ef |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:16de8dbf4edbbc25df885ec593bfa450903579a61352e56da642e8769403561a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:102239ef8d4ded23c18f6d5b1631c22f157fb571cf18dc16f4c3b6b4c85beef6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:e5ea50e178f87abca542b1a426b78cda8089976d51dfd6234857cb89b7536133 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:af8930f772e04f23c35d1417955fd00d3342a74aef8cc2eb40622264c984c01c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:b7cc9815b97ebd546fc9af38b6030a36f7793c03204b15d89a6d7d3e9f4048e2 |