dhi.io/sbx-templates
codex-0-docker, codex-0.156-docker, codex-0.156.1-docker, codex-docker
sha256:e28eb233120f92c561cf4aa5d8b28096e3713f1fa2146d7903ca5dcba797511f
Manifest digest:sha256:6069bbc620508cfd5fd7615a8a5b769636427f6c39b0662a5a7600e877d35cf2
Size
602.22 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sbx-templates:codex-0-docker2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sbx-templates@sha256:2cd2d208f22c5b7cb9830c2acc862ddc48e520696ec784fe16d0a23e4c88044d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sbx-templates@sha256:ccd17469f2e1940ce8ce1e5481d9449a9837ee9ae5e85b860c7dd9a15b46c997 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sbx-templates@sha256:d779b7a6cd580d7a88ad2c79219b68ae37c7a3dd7dc0ad539a09e27feffb8d7b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sbx-templates@sha256:b1a03122751f238a51d6113295b8178d45a325dfdf0aea338d4453eedf066f1b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sbx-templates@sha256:399673a06428fdb712d40b9c39a9f69a59de951d5b0f6c3a833fff8c719d2075 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sbx-templates@sha256:0edb10a69eefe2ed472292a7295767e41233084270f84f383555aa9674f6df23 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sbx-templates@sha256:080a1db20c72d53ebbb532321a6b44efaa082f091d6789eebb4bf64ca1de02b9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sbx-templates@sha256:6ab8e952ca5913909e04b883a3a4928c80d853ef6570d981163396cb8f11567a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sbx-templates@sha256:ea72cb1eae5cf9821449ce273465f34ff548a691945c8c4646c10ff87c94e2b6 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sbx-templates@sha256:e1f7a5313e068b0bcf4f1bcba60d2c4e4cc691b46835a5c392a1f7319eed17f1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sbx-templates@sha256:5c4bc97f0774d7cd863dc1dc487a568dd2d2d2c6e61d899a7df1d003c2b5abeb |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sbx-templates@sha256:ab563e427f7779a046228c5b14d8cf0cd2f82ce21ae8fc05d827108b0f63da54 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sbx-templates@sha256:a966ef9048c28d7a7ff915599c6561c8f1a3f0c1aa78781c747b263edaf934b5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sbx-templates@sha256:6104f092abda86c34244f7a8d940c87f3471b6529944c985b485c8cc9d87e0b9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sbx-templates@sha256:67ad44a79c356e16bbbac924e3206bce450407756cfd0a3eb3b684325ef5231d |