dhi.io/sbx-templates
codex-0-docker, codex-0.162-docker, codex-0.162.0-docker, codex-docker
sha256:3b4b63ba59e808647ad9b24c204dfb23fd8163b89ba687536fd634406f44ad1a
Manifest digest:sha256:d51d7c19541099f2a89f52487cee71d589d35c56a81e422bc0701197a1e64674
Size
613.77 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:codex-0-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:8a893546daf7e7994fa66d95cc172900008a500d38d0977cf8ead276bf43c5d7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:68ac178d6ee513181022240f09e03917929da0f61a74490e2dec4bc2dbaf6ace |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:ce7aa57ced192707f2653d607031ace66d9449c6a5780a577d99dff8f1d526c3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:4183d2252e1e7e86d7f5f0f3f4033c87ee5307d42ff741900aa990f776468253 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:de740ced59e1dfb97e3b8b5951e79daee8ebd1120fdcb127164cf7696d16ef11 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:6df859023e62e436d6e54c9a955122e7371aee73af65510539f1d7de49cb6cba |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:de1be243da0069ea69c82154231471f450a469641948e4b4b993fdd1d20a56c1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:ca8e28603b7cd3578f3d08c1fd854208df23a7dffe353d1943522527727dd38a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:a689522601f1e9c5dec1a0dca76c0fe53800928856abb30c960d5c2ba05305ab |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:c0aa56f69ca4b4029ad32ef70dd9e3fe3cfd168a45da0f1cdd3bf5cf886ef36a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:f46468d5f369a08fa73be2218ca9ebb9c989d07408c0010a9b351a230911e8cc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:a83bd0d4d6c2ae860fabded8667b558af9e9f058267614a85f9d58a9738e3e8f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:e4bc990ac53d5714b934b4c4f2ad606019a9b2d16a5662909e988cbad2c5d59b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:80587eb49edf4992c0df9b80be310f226a457db4ac44385e4089d9a4ae925e52 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:6e2a6416e2a73f5e1e711cc2ae519ac3e434753744b50e2f9e14ac17aad92da5 |