Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Codex) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

codex-0-docker, codex-0.160-docker, codex-0.160.1-docker, codex-docker

Index digest:

sha256:802c5dff842eb0c52c210613d851e89b7b492f3031e5fa10823515b9ea25e49f

Manifest digest:

sha256:759d44aec80905ba2c92641be8edeb99cd1fc6c3d60c4d05e63f7610af195955

Size

613.48 MB

Last pushed

5 hours ago

Vulnerabilities

0
9
14
50
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:codex-0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:3ea5937e36a39b5ae78abe635f3d9a5fed2041e6e21544d5800c6b113fc03f6f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:ca0f85ecf178743f823cb0875cda4477d7a6f4cbe12c9776797645ff0b1969c4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:20d0b4027d72a4488d21b94ae522d4893aac4521928181b4cd16d695838433a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:8e91036e1173be56e7ceb45e28d6b083eaba5e98242794222673eff1b9c9af27
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:fb12d16a5b4c71f92b26bde62f4a28021768c77f3f12836af97a9079443aad38
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:168d8be4d33b72c572ba2f8df4c72e7c02c981656433ec0d2598295d7e92e4c9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:c44f864a875906da632f9fabeaa7d31e37ecb33881c493b30018a872cecf7177
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:e9075c7846fea2487878102eed12f23b172f88ea545aaa9638e9fd8586034962
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:b0830d69701bcb7e4b557e272ea419002704abceab509740fddbebc7c258638a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:a45f524a4d228b851b0b99f1337009c31453f5e0280aba914f0e0e2030dfe3ef
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:16de8dbf4edbbc25df885ec593bfa450903579a61352e56da642e8769403561a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:102239ef8d4ded23c18f6d5b1631c22f157fb571cf18dc16f4c3b6b4c85beef6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:e5ea50e178f87abca542b1a426b78cda8089976d51dfd6234857cb89b7536133
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:af8930f772e04f23c35d1417955fd00d3342a74aef8cc2eb40622264c984c01c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:b7cc9815b97ebd546fc9af38b6030a36f7793c03204b15d89a6d7d3e9f4048e2