Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Codex) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

codex-0-docker, codex-0.160-docker, codex-0.160.0-docker, codex-docker

Index digest:

sha256:4b07dd66fbfb803c5f0c1805f044a9b3fdf394d2f65425dbab22b15e394043a9

Manifest digest:

sha256:c5cc76e02bc4c64de5bafd2562de065597509e85339593dda664dc0151c0c05b

Size

613.47 MB

Last pushed

7 hours ago

Vulnerabilities

0
10
13
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:codex-0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:e8dd0d2773d9c40a12bc343afdcf8cc591d152ffdc177a6775427e517e4d409d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:bb0d47be670c4d7bf1d0ca0f01f329b85aefa6d9b0b615f87aa82a355246be6e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:9fffaf6602079a54f8200baed316f095a3fe3d20847ec881bc851fbd8e0ab5e7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:fe2917c8317a726fe5326b2c32679daf177a5848461abf8dc5e0c0cd301a7fe0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:c604f235ce27dba3782923c7bf6bd2666f3b37d6f07d39732f2fdd150061213f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:6285d0729d40d827b11f1528dabfa0913df7731865345930abff795e302599e7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:950185f5a7d4da9bac578ae8e2ac654c956cdc4063c9815fa1310df57d12f094
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:21bb0bb5bcfc4ab0336ed0ddf609c0daafb4545be1163db0f70d0e0ca5090c80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:665a3c15d958a8165a6fc37a3dc8f75146b9e352376bec8867a6d1db30c914ea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:c20b60fb3d44935a079d33733113f443163c03053f631cf151ad8a512ae128bc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:9b881082f34d037c26d6d4b4e151bc865fc090783ac6dd6599cd1be29522cc37
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:fbcf4eb3a66ebfb5cae1dd209b138ab3146154ef48fc186acdc26cc5a374daf9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:1547db867926d2a24ae32108cbdc7ba555e1e3131b62ffe2183d8463c5845e84
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:ff43e01305e877f0f9146f26d4caba2837337863475e9304a8c8fcda64a34657
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:1d7d537fe00c0005f08958e563f68e7a46c06d0ae55e5038da2e08086c358bbd