dhi.io/sbx-templates
opencode, opencode-1, opencode-1.18, opencode-1.18.34
sha256:49ddbcb953caac0c3869a5915322325fe89e13db21c2856863421b3e3b92b0af
Manifest digest:sha256:bb19f2a08666d84eec6e077cfd1b1173b3ecdcdd0fe19f72697cbe555e972eab
Size
483.93 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:opencode2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:opencode --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:40da4ce4ba30d72094ba2b886564ccc9d3cc07b9337bbfcb1d7b4f2342e581ff |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:796e1fbabc552401593d652b8fded284362993884f0f0bd7c6de31af4be72d48 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:4704ac5a7cdb14786b497f362ac7c42c5a95b404393764a79207df8802ea1ec0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:bb40dde161159fd3273c3503dad92d0022e9a94c22b2641eb29e4f0ac5d0f3c7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:94cde57824be683c80995be08102759754d5a40a1377d225f2ca015aa435b1a1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:2113093881fd79ad0420ebcb7f7432fa5407eae068b1f476959f5d9ba91eb9ed |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:1fadfe1a24a285a2a76d1eaef685b2a18a60186cf281c997a39829639b7bae57 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:a5b054e1c836003984156c58aeb3ecbb67da3d7837a9d0b4c0f5e9f7646fe991 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:75a34666aefb6a32a8e1a36e705eb03111449918580915d423f6c7814c5d80da |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:291d2d57926d33ea89c47c538ca54386be8bde58db078d2a529c500f38bf620f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:933f423f82f3be5384a5d07d4a9a0a57d816b6a8969717930623962865fc3abc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:44e74b54f28649421f5f5b2ee27119a530deb1fdf3806d5d0c15d464e0115ed9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:98a4fe26d3d3ef974b1e150811eec89645f4caa5904dc1766251f6dd1f104e36 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:364348ca51f5e894bff30745d30e766fd52108eceb3c12fea301003c3280c0b1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:f9acec6b043b0bb42ae42cd52396d74df228cc05ece92e72afe6059c4cd4d271 |