Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (dev)

CIS
linux/amd64
debian 13
Tags:

opencode, opencode-1, opencode-1.18, opencode-1.18.33

Index digest:

sha256:e6d976ef8add6d88eac69b64b951bf335d67c89cf5337381864f8c8dd4684f5f

Manifest digest:

sha256:00ac4b97a94fe92ec869fd9e1c0f8048b3f5d8b69b2eff4674bea4b553bbc58e

Size

483.76 MB

Last pushed

10 hours ago

Vulnerabilities

0
4
9
51
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:5f1a2fafe78180caeb3ccf24328ca5d5501d515e3dc586ea3ecb127e91914133
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:c58ae87f95a6aa6dc369822fdbe7c8f4d7e274dd2ae02cc1e4cd967d3becbd18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:62bacb439dcc6b16a27a05c1d7243d5e44b79e325971f930c311de431126b67a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:ba9b7ee06338f78eccc5cd7d19f119b161b132bfbedb17505310cad773fb9c5d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:b5ef6f0591a307cff1e5274b3996cc0b7977cd5b56583ca70c3cd03430852fde
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:06f5c9a536a4c6035cdc70202851c72e02466bd14077f112fc07dee2197d47e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:10786e176430728e08e6d399436780e1e2883fc7c51d91190cabc118381e2e52
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:531d3feb6fb365ee2c8ee1c09c8c3c93e2b5baee7539d7984d7cb48ceb6a3b55
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:6681a20136c656d7e43ae6b813bd4938070ec11ce267741dc8a89cd08bbb2179
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:3c91e5e5c25892fd4bbbab3ebd389d1f612d4847e4d438e93d8d2573b3ac71d5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:404b7dc6f5a42689e05b90d63b92ec4735d677a33e38f53136a9adef9b619d63
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:e5e78c08f43e5c2b93bb1c318bbbe300c8540d9b1d8419c871447ea1063af6ae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:241722a6770afe8879a6a40cc2393b7381ddfdad890231f14cb09cbb08f614fe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:1b844c8508478c4d482cc335a6af75cfb3205d33aa8d5d6f25cedb77d314e076
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:a559c41b3c30ab02a41038bb3f81a507a652b920bc95c0fc32df6a67115f7983