Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker Sandbox Agent Templates (minimal, dev)

CIS
linux/amd64
debian 13
Tags:

claude-code-2-minimal, claude-code-2.1-minimal, claude-code-2.1.274-minimal, claude-code-minimal

Index digest:

sha256:86b8d8c07ed8b3bbe13025610a62bf731d6e202c31ddfebfb27a73c394ee5d03

Manifest digest:

sha256:f7f29a35006d2e8935cbf35aae22fbb355f189d76f336a043e06a9f55a69119c

Size

178.69 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
2
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:claude-code-2-minimal

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:claude-code-2-minimal --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:86f7423c8a1a65ceeb10ac0a999588780486ff178deb6042ba1039a266a7c8c0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:a10ed19a099634d21edf48f2136ad875a2d00cde9bd47995fb9bf5a14adee204
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:0c9633b1d4ceef8ac7d863de1d7d553377b10c432ac1405d93e5f753ec59cf5e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:cf10bd366b8be8e1552aef88b456c657c93737d64efd8c34526e25f166735f1a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:2eaa3de250c1b52ce819d0975d2e665dc5c87c1345ccd0ef59407e9692d8c4b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:eac24de71f956d531a39b9747f7b57ab5d27972ca5fd4169dd9824a4cbc3e27b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:b2df3de8c68ae74268613e35cb96eb8103ec2c0b2e816c79a07b6a2f2a27d755
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:034c86411b5253e4229a414de4408995a474f2410b399c8e540af2b1b1f56f8a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:12776ddb32accf2ed48d37791fe9d47f03eb2436471150371583e8893381d25b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:f944c470bd605e93f91387a45d2b15a3480734a924dd1b3e3b1349393a734e33
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:85d1335c91664ba98a53dba58eec9e2ce9b7ac166463699898a7ab7adeddbe5e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:66e2e33c5157b4b797e3a8c78045b116c5cabc71d9a14e6bf33fe6478d42ef52
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:dcdae670d4e04e3a201165f22f5fd58998293a42bf0c945019a6f23be782ddc4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:46f05dbad48b0a7d2249857e5a203b46efaaa3c21d8c522cc4c8bcc77d1952fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:91a75e834b9203770e0e64033024a95e91f8bd98f71230431575718a43dab536