Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (OpenCode) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

opencode-1-docker, opencode-1.18-docker, opencode-1.18.31-docker, opencode-docker

Index digest:

sha256:4734619fb7741208811a69893774e99db81c82577458db12ef3b326ba0c313c7

Manifest digest:

sha256:be1319ae8d34110bf9e4aa0866606ffb68e6ab2a1b28f530219ef25ffa20b84c

Size

584.76 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
5
40
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:opencode-1-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:opencode-1-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:3f22580042f81c3bc00d05d4e2799605a15ec040ccc2c7365fcf84b52cad31f4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:579ec2f1e68c63625f3d76f9807550a5e0d2ce414d74603508383fbca5e8ec23
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:3605c37dbdf40c14132eba86981329471db41143cab72a8123bd5ca9f49c5bae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:1cb17dea032caf116a02240f91c599dd39889744f35341f45e6fc0d468aaf874
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:1fb12a9eeacf2886ce880151f3758980da9d112e0a102bac32a2ac41072d5b30
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:7f30ac99905645b7871260ea174b04afa29ef5d90f505cc04a085af3c8d2b59a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:1a9072d0363298c825f5dd1eda2a2fd0d98c073d9c22688dd14046e2b581777a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:24de200ef4d4c9e05dcd45391a3d40330326d1045514d51f7eb336dd3aebc9b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:e063d2019615fb278bde50b622b1b7990f6fddee5325c7edd031a0ad509a227b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:a266d81605cff38dac75249f0e5d31d58d155f9c6ae3648d6e317eb4a742f79d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:3c49d780b69e6041e2d75aa2c5f5a91b9df352fe7625ebdbdcc8fa0d79aa08e8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:f44d843c745193a72752979ca5cb008fccc84d387b33bd7bbcfd56944d5232ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:c8f5e799184c9291cc9a6da550e6a09b49044bf611a75633de00e889e5e58460
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:2eae522c29fa1858fdb490a9eb3bb9dfd1a84b31132132c6f51bc900928d7345
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:fcea55806c457431d3508b6b9eb168c43be08f8be95b9b55d4781a2dc429ad34