Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

opencode-1-docker, opencode-1.18-docker, opencode-1.18.33-docker, opencode-docker

Index digest:

sha256:bd478a93f4b758c2424701fa320ca615562df537eea3bc8dfbfa9fe62fdc3530

Manifest digest:

sha256:379bf5808bad09b55bc6610d0fb86c50542efdd254c6ecf2e9bdce0c7d60fa9d

Size

584.93 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
5
41
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:68d5bf21f802bbef46583acbdaa706b18b7f96960f03c79d2a164a61203cde22
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:67c17013d0647447ceaf1bba5386c329a8a6bbdeaecdd5047c25c13349397ef2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:2e94f794d13214217edbab0b4c078c120eb9870f4227579e89089334f5e14d82
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:222688e58630f3f11ca65f7e8316ee239c202da8fbc70ac2d169bcf3ecd285f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:9977bae2652b4ae237f9159e8e68a5ec979307a9dc75e1d3c271b01c2606915c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:79f1e94d9b15723b06104a05b7d13b410fd951da17227bda075cf976d935a874
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:163dc734ef4c625fce19a2ae7fb9512010d79471f1350c42bcda557d4dd2550a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:50abbeb2f7448cb71c52d29ad44352e5007577cdafeb151f0001aa722ab10fc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:7edb345207d5c6889b05199d6d9500d0e0ebaca3ccd7ff8065e54ded50d58bfc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:48b0383d3280787f868d9057d2290d4a858acbe2b2099c27602435ebfef44484
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:1d868b5cc8cb6980e5c073c711852376e58cfa7431acfbbcedbe9b7c0de7d775
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:cee1cf70cd663454acc21bb84deb0b88539057289715721857e865114c89450c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:3166cf1198f83fc5e4630bbe7e9fe64a89456e3029de03f9e41ae8705d24615e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:118f33ef0cdaa0891bbafaa632210a5a13bd185f31e39424315e4d555394887a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:37591cd23cd3a38cc6e9d236bf37355df94c2f7b12e2627e84aff2d190236966