Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Cursor Agent) (dev)

CIS
linux/amd64
debian 13
Tags:

cursor-agent, cursor-agent-2026.10.01-e373342

Index digest:

sha256:cf455a3cc885abcad241bb7cc3ae807b88972bf79ec65eabf8a8446a14f30164

Manifest digest:

sha256:079cabbfb8aed53462068b3fd1af045a5454ea929134d40a809488705d3ddc5a

Size

527.73 MB

Last pushed

5 hours ago

Vulnerabilities

4
19
11
43
9

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:cursor-agent

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:cursor-agent --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:c302b9d4166a2a8d40b917635d28a6703e115520b8e72f6560ed229b7684a3e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:f25347cf0a8ef6cfd6830195461538fe9cd21730242c7dd35661f0e04a45ac95
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:cebcc35d36b09634c7f2ad1b64b2cd45aa39449d0e9496b0ef7aca080e5d1ba6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:8d12310aa6407e300673113fc5dbf0ceb9c8aa504a81b6ac08ef905a5e6b7dfa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:95919c9dcd3b468a9ed0991c9adb02f19fb9a6f805db14170052fe3a1696d2a3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:c00a1cdeb9764119cc9df6c0905acd9c526b3bed4f8f3150f759932899ac347d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:005f909a6cb03a27f40c9aca2b8f8f90b7fc5482be3385d083e65e07ff3b2247
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:ba6444f38359e9c4240d9e6b997971aec56bd95391682a7b8f50be00c5042227
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:7543d5853b2762d3415a6c803b539d6b7a785f4de06b5a47b23a4df734daee18
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:c22e848dedceec1d5c4e5fe79802288ba3964e9b97ed4c72fa824d2c252a71ca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:8ae537921fce0d065cb222e11251dbae23393d97d6328107f7d3e20e47408bc1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:1e7714646178c8ab37aef2493e1d04e5c319ac20a21cb6695c11ea662092bf6b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:af65cc6dfc0d2b5a207ba8af87e560648e5f1e2ae9683c1b2c96061ec3da139c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:e13e2cce206c5cd322f465d3e2433ca18829d179c5cd41ba46dbcec715d49789
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:6fb5a87be90f6ef4ccb5a721c09fc7b8922b6f96da1fd9018edda41c95c1f0bd