Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (dev)

CIS
linux/amd64
debian 13
Tags:

opencode, opencode-1, opencode-1.18, opencode-1.18.35

Index digest:

sha256:26c5a9ca1299d689bbde60d32ba4562ebe74b9d00b984fef4a247a6654623b58

Manifest digest:

sha256:96e8f78094240d4ff138d56e1dabb30259b465096e3df45c0abc24096d515d30

Size

482.02 MB

Last pushed

13 hours ago

Vulnerabilities

3
13
10
44
6

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:6f8be9503a8d4235fe635522d88bd3919828e6edede223b95112cefb741cff6b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:0cfaa6f908b9caee3c722f6ab3c33876812493f48a3c2120ca03a9aaf0d093cf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:b85feddc1dac1eea3e748e64954dfc88707e0d5ef3c8516dfbea62a2e0a7b7ac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:2ebe5201e05a8556ac34345aa4f2c45d188ee8e91b7167fb23a8311d0b6a6111
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:867bac72ac544e80fcb266b268254b351f074559986455b6d677eb56495c2487
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:5ea6c81f21de3e23f6253a9e29346f5ac9b744c019ffd828673b3ae187966388
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:9bfdb93220b71d04894d9e60de8b1b8101f4cedd4bf6f7cda96de83761a373b1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:53a2e9d22d2a7fa7ed7f8aa25e9459bad25f30d789a7e91bb2ecaff113fd2a78
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:4e9bd95c334216badfc5c90170a6b5217ca787eb4b59ab82fc3262517b104e0b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:3b6fde559d3fa77458176eec876f789c8b176c5f3aacb04edfe92410bd4e6199
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:869edb893a1b04b5e8ffaca815203a1180a16816ee63bd504f10226fd83ca3e4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:1f777a54ac81da2c0113930f290cc2d1f8e4bf378fa9b824e725a4bc353d543e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:839a35638051e6227c2051308a9af7da79419536453b61fe771c157e6715ff27
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:c40684bf365d0447b14ed9802518853b84190c4a235cb39960a3f57dcb74773e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:5e0332953d09bb37d6fac669f980a4158271b1080cb490ef83fbc0979ceae38c