Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Cursor Agent) (dev)

CIS
linux/amd64
debian 13
Tags:

cursor-agent, cursor-agent-2026.10.01-e373342

Index digest:

sha256:247c814153802f1d5411305ae8b0761e48f009c2cceb168e6efe817b211dd247

Manifest digest:

sha256:fb9db290d77d1904ca481bca6ac1d3144741ac9f68a6b325c8e263d985cbd321

Size

529.87 MB

Last pushed

5 hours ago

Vulnerabilities

1
6
11
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:cursor-agent

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:cursor-agent --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:b53751980db51000d3dddd8babd3ffde36c2567f0983c13012c896d3d55afed1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:7b302871054642f56aef7592059776ba51258ccd6016b957596926655a074f09
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:0158861e67f5c5e590e7d5d1cdb257aa71c071503cc3172cdb2ed9cfae8c5569
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:6c0f4dc81aec313eb6b9e21cb2dde94b385f1c63afe9cd2b688fb1601e380d91
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:0f2094ca5abdb799100a3bdcd9a6864623bba08ef118811e61255b67a98e6e84
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:3d55434bd2b13a527bdd90ace4daeb12a899812d3fb73e274e56cb11724107e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:7e25eef95456eb734824c99ac33a56710f73bd87fee6283bb4415ebbfb0b7d82
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:ac708ad792d417f77b438b99d27b3c0c3e03c83a64ead5f52dd66c8bb7e01ae7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:e3ba5d4570fe2e297643a516a580280a27f2f1c8843af3d8810d7959172cbef1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:82391cb7678f64f63ce92e048ec59173776037caed9060f0c134a4c0aefc94a4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:4a5618cf61c2b4f48f2610c30e8104a9d498b452b68be4bf349309959f4e994d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:c96262fa0dedccc6b4b2a733f5fc5e5470b842b1cc7d2051a311b2679dbd5bad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:4b0a4e7ed7fceed9a77e1c0f4f52b83723d4ba32b1217e6668c69e0e1c9ffc2f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:253fa8c4c7e1562f0219ea3e295bb406f218cc9237028be7f06fb3bb477e6a3a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:7b8d52a454d1dd55e3a7a4d81a654b3ab7228e83c5f0b549814179d3153854cd