Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (dev)

CIS
linux/amd64
debian 13
Tags:

opencode, opencode-1, opencode-1.18, opencode-1.18.33

Index digest:

sha256:8587bd8ef9aec39934f756bf999dc5a827c494ab64ce427720182b31e03408ca

Manifest digest:

sha256:0f9b180ea0b316d31904a4e74ba97c88db07026a1d8d022e0b5702eb3582451e

Size

483.76 MB

Last pushed

4 hours ago

Vulnerabilities

0
5
8
42
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:fa7f88bcc3b05e7d2d59f8342f6c671f9e41ace2a49c178c8bc390b8cdd593b1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:1955677105f713a56e5102b1bf9c2648cb3f04a586ae33618c5899cb91baebe3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:8cfd60d36face42f90c80e045304565850030314b69c196900bc0da5de265b6b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:1055ed64a082fe382ef4bc7551b200f056c2178a55fa952980f66803342d0786
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:5e2412a940b0d98e80e21608ef4abf71b4d3ffe1f6f55c19cbeb6b8472921356
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:e9eff3c2efccda3a3b7c8d130d2fdd189759e6626321d56cdb5a13769343885e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:14c0fad505cd1ce4b8d41c6ce5ff1564fcb4c36f4c317dfcf957150d7819a2ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:a916362694033af5fe7617d837efa9a375d8201d45693f6d7aa91fc91b96d718
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:d3f70313390477fa828c98c1768272d862483e92e2b4165a0e56f09d8b581c0c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:cd636f4ed27abb958bc553088ed1ca450448cf8cb9205824110296e56acec9d3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:d738e8c6fefdfded43c52f52f07fc114e08d719ba758222604a6d3e7ea2705ba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:81b27d5045fa42dd13b8385f573176daab8327de6f60ae4c9b9c1b9446e46b3a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:758efe87fcdb9843f821ed4e0fc777d96b04f2bed8b4b960325d89539f70021b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:ea7ea46db201b71a806e287665ae2dbd479bb5045760c4fc4c15844c89d56718
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:88eefbdcef11d74f44b249927e176c83b4e3d2ce89ca80c64b1ade7d10a5d708