dhi.io/sbx-templates
codex-0-docker, codex-0.159-docker, codex-0.159.2-docker, codex-docker
sha256:0529fcace182dc3de0967bdb235ed3f8ca715f8eafc9f987a53a258ae3bf83f3
Manifest digest:sha256:89fb49e29098933f2c3232b7fcea6a5f6ede5448a8d15eed140e1faa1f52e051
Size
612.57 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:codex-0-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:5e623af2b181640f10facc2cc618754a0ee69c655edef5a78f4aaeee9aa371d5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:78bbd998ce62d9608e8453546fad187271eb7dffb8a3d3cb43c3a78f79ba3732 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:eb707067d2523d56d4b5cb4d667165d2a3190641e4e6c2388ccadaca704aa784 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:1a5350f3655fa4e73fb6f6c560d2e452fee25e0d3b86149b864a36d693588615 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:1b04bb4b053ac00d18c48c57a67e16974fdcb65902f8b5d16230301e06e1fca2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:65012538bafdd15215d18a6ecfbbb556285d0141a58e7f0ff4f6ecff3c960c2e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:b87e5af61f099f56dcec98cebc865c7dd5f3e0d1d039fe98fe9c5759ac383121 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:7e970fe4d1de65b0e2d76de0b6bce069dc8ef058c76c133de45930af871d949d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:ba030a8e787e0e89a9d2c876a3e8d2f4ed27e310c369dbf78625cae73ee04fbf |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:5b28b0bf1f81cce887886f47eae3fb372ed9891c9795c57f76f683a84de66043 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:93db30ae09fe61bca9c39c6c6a99bf2fb4b20d4a4cd73171aeca8161b5046cf3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:7e74a7651eeb06fbcccd929060a0a0b578f01768638c40178124d5850b47c188 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:3a76f15b393c4fe88b78f24a02394e3b9ef826829e1fe4d589f8c1ea9258c935 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:92168d9b429023e92791705793858563a78884a05180e9deb0c1fb0cfdfeb77c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:82906fc8c8b5b8ec7426bc37a589ab1a443b6746ea7b18f882d2b89660a0b0eb |