Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

opencode-1-docker, opencode-1.18-docker, opencode-1.18.32-docker, opencode-docker

Index digest:

sha256:3520931ac2d11242b4ebe3b6447ddb8373eb74c01a5fa979842549468d7b705e

Manifest digest:

sha256:3df17e38daacb7e0a7b03202d6677393bfc4ff58a04210a6821a62b23c6815c4

Size

584.95 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
2
41
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:9c713e91d49b15cdf60f8c876701a5f0c626a841e780a6e1f6e1abdfba3f6f4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:b3e0fef7fcf3580add32d2a434f5f577bbcfc9064cf6abfdab562cbce9711be2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:93d17704ff4dc320fe60b55479494894ababc995407ea6989f5b22e0adea04c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:93bc2a046c1b23f5c0023d06b0fab5db795c771c7f65a419c3c773668daa5b51
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:ef156db750d13bf26d49725e03f38bbd1dd6434ba99c36fce3b942cfaf36346d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:49a9ce89a70a9a60268f1479c8729a279890c57d099dfb1d0887b823937cbd48
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:0f6eb684130f5607cb1422294dc7120421b08208043f837648716b01a1fd55af
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:11c554ad99c8d985480974af099c2eb4efe5584431cf27228c1f56b8c02f133c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:9a29e0a807e4c1d28f07484b80a008b6f57cc4614e61a623452b5892cae652f0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:71ca498200df02cca15767cb852e16a17920f685f927ff5462e169fa829983ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:b815aa34ade1d2ea112bb5ea90745b97a3d6b27f4d11dc71b934756e205a3958
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:a24568bc83c6151fda742f7d0750bc382b6198602b70b11b3f47ebbda405fa18
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:525bb97fc6bc18319c30d558838b50463cdb421a047db970537f1686eee824ca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:d677ba88dbc574e55c8b1cec408a6a3e6edb999571aa6267e9630dcb7933858e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:481e9f6be2c15b98935ac2d71a5db371126ec3675d12f1fa6c3bdb6e19ba1536