Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (dev)

CIS
linux/amd64
debian 13
Tags:

opencode, opencode-1, opencode-1.18, opencode-1.18.32

Index digest:

sha256:d72c9dea14d2f82254116f50ad2ce52c31c23b6686a9023b141d13734fce0445

Manifest digest:

sha256:79d5b5265a4c403fa2826b88edfe1b98a1bd0fdf153b25cfc1b6d1ea65f7d3db

Size

483.70 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
41
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:9584d220b7c60a32d5873daa1675bf2946a311f2b7db60916ba26ac5cf02d961
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:3c437742f15a038bcb076ab77e5cc42a396ef32a9ea3c64396177f4bd37d8660
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:dddc2b6a75d1859acde96f9596d930114ee2157e06d7ba9d95fb9f4a963728ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:9528f261c892a3be7e639007309da58e4a5ae485693f3cd3b33cf9b5ad8a3fc1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:1a8ffe84f6dc077692f2b8bba69faa700c3d38d9c7474f5a0e4c5737cdf1a321
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:2f204c7e5cc052ced8725ed6a0580cd3f5d3f5baae3a8ecaf5e4d94dee2801f7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:291d9996497ce8ccd692fafdec5705c6bb4aacd1f8f995fc1c036fd18367c8cd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:1e692b5d5affde8076db66f9e623d35000f87b5c4206e8a3c92d25d4b9b80d38
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:3a8948becf931dba057a6e7bb475a0519b84f3700b54b5b58b6b01ec9f2152f5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:b1c94aa1a8e5456b2b7802ce14d2ad37b6585c2ecb6ff54389b9185768d5003a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:5bbbf698b3508a957ad318e9d09b1cacb05f2db0445d6a5c05e59b0b54e67b33
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:e8b9b8f4e48572d78e222be4afd5d0c79c7a44f3e244a0c854580105c0467c8e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:aaf0f405e3756614550d5bdf0e028f98d40339ffb52dd699a74cb98ec7e8f712
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:e3c631cf0d12a1b81167030a4a4941f895032b8424c90c0387ee08cce6121e5e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:4859a69105372958bc5a2701f56b1191c91ac6fabcbb6e60920ba15f2d4d1fd4