Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Codex) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

codex-0-docker, codex-0.160-docker, codex-0.160.0-docker, codex-docker

Index digest:

sha256:112840191b20355a3e04e7b037f68510f4016382665f02595aae823b26fa0230

Manifest digest:

sha256:d39aaa79da8b90f5d410b5b4ddedd598a5c13ac79a3b3018161af1888c61439d

Size

613.47 MB

Last pushed

6 hours ago

Vulnerabilities

0
9
13
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:codex-0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:f0bff9141b73f5aadbee75f73350c7743e56cb639d092887f92bf965253dff17
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:dd3317135141301cac1aba3581a75455f10983bdd8408cd7994e2f619791190b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:549e3b7269ebd30d6004d54c86d91f8d6fca101f636573b468437d71369bb2dd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:de765001b79ab3580a1ba36144467157887529a1ed17446f7d206b223374b1ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:e40877ca4b6c5a829cb1942e046a734ca878d9c86701ff3f4d536a9248c4e981
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:522239f0c69352f3f4d1d24538dbc76b16d444d1b8bff0a8ec25f576f01de7a6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:fa693f3a4e8dcf95fc4bb53a6297d479e069cad7c9fd89a2e54431784f5b7220
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:df4e554a1d4459899aa9068bce58f2b6c4f80fb56f215523ee0c4af9a8de3e0e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:6042c6d0482f3c4ee7b1a7c0d8199ea3c5dbd6bbc0d40f6cf9d0fd4c7d53e04e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:6babe968aca0e2f0d5caefe7688355013225a1cec6a00cbf2d816d3b69561fa9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:c83d7b11fea0d691267a2ff8563834cbff58f03efe9c498274e6e2a0a359bcbf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:adde521bc62c7aaf752d3925cddff088647aa62a84703875ee063a26168045f0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:f9c9581c70615d6ba77c5664fb90bc6f6360cd5dbd8dbd3ed1df46777518e761
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:745d2d6bbc19443dcf288ee92c93f7d1598e15baf4106a8fc0837d0940d2a2be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:4747930b9e7bd3c8b1b8467e9ba5dfd156abf620821e76361ea93eda2db838d1