Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Cursor Agent) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

cursor-agent-2026.10.01-14929f9-docker, cursor-agent-docker

Index digest:

sha256:5c03349708fcfed563cd74f709c4a3695bb80546edb9e795a6f4c0258c9cb4e2

Manifest digest:

sha256:7949e8c18aaf79fa63f8a0698014e4de398ae3cc88214d1d1ad81b4b15d5edcc

Size

631.05 MB

Last pushed

15 hours ago

Vulnerabilities

1
10
10
42
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:cursor-agent-2026.10.01-14929f9-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:cursor-agent-2026.10.01-14929f9-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:58bae36146ab7ce7f47912440d641ef2c09c88b59a6353967a127e753092badd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:915bb6caf9258c8d361b1b5d62cbe0cf93409c82161b1a300d159abe8685247a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:46b8a78a30b2b77d09e9d71db43ad7a4935c80916e7869a8b42f3c2a76a326e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:bf09c70461d5f5032fc4d45c8c4ed9e3b29f4227c617118091655332a1690caf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:b943e39098645343cd92cfa22a76da16e5e85cbd474b7f38bb660283a12f1e5c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:9f59ac0869a285b7cad6dbcb9c0149685121b48955d87eccef8c6ff5a00f4545
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:9a406f12b1818253d7e5e7564b782f35d177744ecc819d09206f741196e60d0c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:9e81f95a8883b2c982de4af6645d86daed8ad71e1de6002a4e181bee07588e9a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:e1e80334344cc81c50338fbb8643d27fd979ef805af561f1cc7b8b79f45cfd6f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:91bee8fca9b2ea27bfdc613df5bb3713701567500e5d5f1c8db330e20c3ab592
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:f60841bef8dcf1e51957269541d5c1a9926a24ea1d9290708ec2fd028de9cbb0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:7e0eabc1f05fa9ff3de3187e953afaf47aa1d0121e04e368f202cd27bb74358c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:dc54ec7b4389ca077a01af05cd247df040efa5f09a697eb39aa8611e24cf715e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:5fc47bcddf466eb0b3c69d18b4d1ed5b6a4828b5ae9c47241320fda1bfbb41d2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:feccb3397c19058b24c950b84158dc9a58641f31960c6463829260d4f0ca4735