dhi.io/sbx-templates
opencode, opencode-1, opencode-1.18, opencode-1.18.33
sha256:8587bd8ef9aec39934f756bf999dc5a827c494ab64ce427720182b31e03408ca
Manifest digest:sha256:0f9b180ea0b316d31904a4e74ba97c88db07026a1d8d022e0b5702eb3582451e
Size
483.76 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:opencode2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:opencode --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:fa7f88bcc3b05e7d2d59f8342f6c671f9e41ace2a49c178c8bc390b8cdd593b1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:1955677105f713a56e5102b1bf9c2648cb3f04a586ae33618c5899cb91baebe3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:8cfd60d36face42f90c80e045304565850030314b69c196900bc0da5de265b6b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:1055ed64a082fe382ef4bc7551b200f056c2178a55fa952980f66803342d0786 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:5e2412a940b0d98e80e21608ef4abf71b4d3ffe1f6f55c19cbeb6b8472921356 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:e9eff3c2efccda3a3b7c8d130d2fdd189759e6626321d56cdb5a13769343885e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:14c0fad505cd1ce4b8d41c6ce5ff1564fcb4c36f4c317dfcf957150d7819a2ae |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:a916362694033af5fe7617d837efa9a375d8201d45693f6d7aa91fc91b96d718 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:d3f70313390477fa828c98c1768272d862483e92e2b4165a0e56f09d8b581c0c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:cd636f4ed27abb958bc553088ed1ca450448cf8cb9205824110296e56acec9d3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:d738e8c6fefdfded43c52f52f07fc114e08d719ba758222604a6d3e7ea2705ba |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:81b27d5045fa42dd13b8385f573176daab8327de6f60ae4c9b9c1b9446e46b3a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:758efe87fcdb9843f821ed4e0fc777d96b04f2bed8b4b960325d89539f70021b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:ea7ea46db201b71a806e287665ae2dbd479bb5045760c4fc4c15844c89d56718 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:88eefbdcef11d74f44b249927e176c83b4e3d2ce89ca80c64b1ade7d10a5d708 |