Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker Sandbox Agent Templates (minimal, dev)

CIS
linux/amd64
debian 13
Tags:

claude-code-2-minimal, claude-code-2.1-minimal, claude-code-2.1.273-minimal, claude-code-minimal

Index digest:

sha256:0335e34f334216fcc6c7fb74ff56db124ee48451cda1903ebe49e96bb702508e

Manifest digest:

sha256:f2f861f0ed814dbb895861cf146891859bae7b4602901c41e1f68726b2b35de4

Size

177.48 MB

Last pushed

12 hours ago

Vulnerabilities

0
8
7
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:claude-code-2-minimal

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:claude-code-2-minimal --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:c309711d82a66e899d1efb1e21f4ca075f225d002514ae5a4b9789f8d3208daa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:ae8c05c31f5494985d172cb81db71317acab19f9908416805bf18a279d38bb05
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:6e3dde3640c9be29f213b930030eda5bb4e236e43feee47d42673498903c759e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:107bdeb272e91f12bb4cd957a03b52930c2c8fd3e739b9e4e1b66a83a55ce69c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:ecb184956b7e6251f868e5d66d35cf44e42ee4f22c4246a4b037e78430a0ae11
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:3158394cde937ebb536ea8d4f8442c9aa6212c271bcabac6c7f60c595353f5ab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:2cc5a75506e7c295686009edaa8ba867a205cf77540897593acf0b596cc69d4e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:56b3b0454209b72c87077ec38eaa8373f6299521f96612b87224e1edf4486fa9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:9343d5984f8808a5ab43dc13cb391293b96b30605ade88a6ceaee8315578c2be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:ef965f72d3606f94a39f0ac7765f34bf868ba115200eadd6983421de86866182
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:f1f9e838f9bac3974271396fb490c3fe3dd578615e0e7b2b2bb796d075092335
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:7fe1507108eef104c4b675ff1352a007259297ee389bfbf86a8b38d8ea3fa3f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:3f260beb7204786976dbeee0d8a7192c6b31b49d2da3efa5ae7e6ae9f270b876
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:d8aad03d7919b4bb719f60f7165455155ef3ec112c3b4a96ab6a921a8af346c7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:636a97b94f6cd4fe37827858620b02e3f11f89250c35649e678905d600026a01