Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

opencode-1-docker, opencode-1.18-docker, opencode-1.18.35-docker, opencode-docker

Index digest:

sha256:8602dcdecb9924812d17d6e05b7c7dfaa5fba266550cfafdc6f43bd366b388c1

Manifest digest:

sha256:35fddfee56478b102e240d6396364bc936a498014603bc1c2d906a0d7373cb13

Size

585.93 MB

Last pushed

11 hours ago

Vulnerabilities

0
10
12
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:690c9bd5901ad14d01574005ed462d7e005d5a93fcd5b3883c4807f8c5322fab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:59673b5a182beb580a131a6af03af206a847eab08701ea5a2a440a98b61ab052
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:d455b56305c48cc20115e236120ef37fe78d87bb82e6f499758691ed3100fe48
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:78b23fbb48f2620d3ecb1b76539c26ad7540d09dc9fa0107a7f6ea5ce059c391
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:a5201da158478ed5ea06788b6ef19e9dd230e6193a9acd540d83f32bc1e437cb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:bd4ebdb165748cef0ff691dad26baead34769ef68a5d0b56116ad272a9792c68
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:c6c9f492358213d4fb0a47ccf1b369cf840d916b67afc85b0b8f770a4b781cff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:d2cb2d4d0a78f6724d96d200dd0a878098de72a6ea5e64eeccbbbb886b58e10a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:d0d2181bb5e8c03af0f4befa281845097031b0808c65816b60537426ac3d0500
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:7a448802e74026b9e92a748866de8fd6ab39f6a34abe55535c95544bf8fd9e3b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:397a505db1f354b3fae7d944b0600592a1f490e11c4879b350e8e605abf03973
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:813681fd3b9e8fbdc884c7538cc3f9c23f7f05184df5f0b4cf31a68d0d565ee2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:dba0ab19f77a2361f1d5f19cd79e2d3c78c4de85c1f23ab97bc7783ba31cb598
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:6615bc2d82487cf3782898886fe76e396942e2d526fdbdfa638d02666178a58c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:191ffa76203330cfdd9dec17fd2976de959ebd03b1e67a86df5769c16415b4f9