Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Codex) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

codex-0-docker, codex-0.160-docker, codex-0.160.1-docker, codex-docker

Index digest:

sha256:aaad0e04bddedf6c4ef79c5d875f2085bb8ab4df2196f6fe3e1a2bd97fafbc11

Manifest digest:

sha256:bcede85240be6a68067741e697267788c721d7a62e35345131524c78c09b2ea1

Size

613.46 MB

Last pushed

9 hours ago

Vulnerabilities

0
9
14
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:codex-0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:0e798dd22d5c60b9ecb548d46a8342645747bf60d47bd4e0ab52b3df02e1a1bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:0e95bc0109fcefcbf40ae18093dc382ae34b3b117763c01e4f156ace44881775
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:f4805c14183764b8b6f041600b8a0f9d676fcd45a0a0f071e3cdbb9b21dd79d5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:a29b72f1ecaed1fdcee3e3ed6804978cf326d807d771a808bccd9056bb3e1a3f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:7bb55efc35d9b34b4984506e53c499a2c546a3833d93feb06a5caf3e9469bef6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:ed527584d387a6aa1ac3377fc94d6c4cfb189d0ee6cc46f4c5124088a8e42906
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:1055b1c65eecd93120c5e5f4d5e683745bebfb8fd0994721021dbdc90841a3a5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:2e4b9c88ca8d4f58cbcd4bff8dd7f7f612ffb360a451258f91237dbd40a2b5aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:d8967f9c9e5dad7f54391ca47dececa2ae701d1f3d647face86008e4283213fa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:1dd7f046a282bee170298ae74549966ef8dd2188f890b8bca6e587a550851639
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:d8377cd9090ef11c41c441f3f6a54421a83ae751a1027947783f553d03e89712
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:5d4e835287de9c20ad3e73e53c87431883185b864e92767ecb2d86e6915b6004
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:35a6d7b91ba13f5383541ea558d0292a69e5170a2a2387b65bf6731012d9494e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:2ec800384bd0b5ba94e1cce6d086b463eccd1da909dda94bf6bdc02a917e7ba0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:d464d9da3dc2bc3f202360a68f162c9f019fe81d416325ff4dcca7ea861b53ee