Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

opencode-1-docker, opencode-1.18-docker, opencode-1.18.34-docker, opencode-docker

Index digest:

sha256:84e0b7460d57ece3557d4b9d4d5416f42805a6853ca3cd57302412496fd98b6b

Manifest digest:

sha256:f694d2830e4af92b58d8473b5ef9dc280c97fc2d7b83713a7910922e282a5a59

Size

585.32 MB

Last pushed

15 hours ago

Vulnerabilities

0
9
13
43
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:524f7e59d16f14a99be6faa30c746c71c820f7eb988af98784bc3447dfd9589d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:e6797758ef28afc1dbec09885f510b91493e6ecf7cf9e0ee01f3a23403d76f2d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:3f13f67c7974c06476f779a5b9cb56bb8b488dae8a4cb294c5da96e1abadd00e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:0d9f2ebe586e7d3c03d6efdc87f6b8946c1acf4a898ae818cd0491a5f7f70bfc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:e763b901442f93ebfa01d74c134578d855aeffe014b95c36505bf1db56c037fd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:848ca75f30cc6b0e8e249ff15d3bb52ce60ba9f7ceaad88703662dc54743858c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:a8fbdd7547b78e4b4a91d43177c0b07bb530a3d21799887451bd2a25c439c320
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:fcdcaa2f1dde80849aa3a9731700d0ab8dd8d320027772f9da6b0c1025ee3c4d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:cc51ca75f8c7589712085b43d712ba8d82f9da3f0175dc5610b1f2c8d9f9dc94
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:c3a70d08b73c6e5b8eac95997744ac194857eef19c0ac752ef27a2a1c15391cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:94982c040845200d20d293d9207c0ddd52053e9844e0ca60888fae52c7579073
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:ba05a1f66145974e51f8f2708db33c336a740e6c624345b7105fcdbc09981bb9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:6afc5e812c1846e7c8d75300bbc3d388f7c60ea3d90e4e6c6a49aee9cfd3f73e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:9f9f8d683e3f6808b5e940ad4ea4a8ebcdf43f67211469de9f1f2c51cfb14bd2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:38f616712e44257a7a8184d73de98031bb264409a7baa6a630e085b38de64ca8