Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Codex) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

codex-0-docker, codex-0.162-docker, codex-0.162.0-docker, codex-docker

Index digest:

sha256:3b4b63ba59e808647ad9b24c204dfb23fd8163b89ba687536fd634406f44ad1a

Manifest digest:

sha256:d51d7c19541099f2a89f52487cee71d589d35c56a81e422bc0701197a1e64674

Size

613.77 MB

Last pushed

3 hours ago

Vulnerabilities

4
22
14
44
8

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:codex-0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:8a893546daf7e7994fa66d95cc172900008a500d38d0977cf8ead276bf43c5d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:68ac178d6ee513181022240f09e03917929da0f61a74490e2dec4bc2dbaf6ace
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:ce7aa57ced192707f2653d607031ace66d9449c6a5780a577d99dff8f1d526c3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:4183d2252e1e7e86d7f5f0f3f4033c87ee5307d42ff741900aa990f776468253
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:de740ced59e1dfb97e3b8b5951e79daee8ebd1120fdcb127164cf7696d16ef11
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:6df859023e62e436d6e54c9a955122e7371aee73af65510539f1d7de49cb6cba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:de1be243da0069ea69c82154231471f450a469641948e4b4b993fdd1d20a56c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:ca8e28603b7cd3578f3d08c1fd854208df23a7dffe353d1943522527727dd38a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:a689522601f1e9c5dec1a0dca76c0fe53800928856abb30c960d5c2ba05305ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:c0aa56f69ca4b4029ad32ef70dd9e3fe3cfd168a45da0f1cdd3bf5cf886ef36a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:f46468d5f369a08fa73be2218ca9ebb9c989d07408c0010a9b351a230911e8cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:a83bd0d4d6c2ae860fabded8667b558af9e9f058267614a85f9d58a9738e3e8f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:e4bc990ac53d5714b934b4c4f2ad606019a9b2d16a5662909e988cbad2c5d59b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:80587eb49edf4992c0df9b80be310f226a457db4ac44385e4089d9a4ae925e52
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:6e2a6416e2a73f5e1e711cc2ae519ac3e434753744b50e2f9e14ac17aad92da5