Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.121-debian-dev, 1.121-debian13-dev, 1.121-dev, 1.121.3-debian-dev, 1.121.3-debian13-dev, 1.121.3-dev

Index digest:

sha256:a240565a2eb8706ac369c50d6fcbb6eaff79c992d3e8216cd4bc8a4561409eaf

Manifest digest:

sha256:8118d0b8f678758cec43f205c8fbf79c3e0926f13d7d93c74568b883aaa37869

Size

86.73 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:d5bf67155c6266056afdcefa7716bf49c69e1324b7ba7044b1338ed1b4a8fae6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:08b5d95ae6d2f5e5321bcf0b900ebeeebad67cf99fb5639a21dd90959a22dbc9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:29c112b74d5e0a00d2382c28eec0472431ef8d59f2665428f676496186bea242
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:c0809e914b2f1e5828e6c2131cdc7ce31080ca54c585c10351b035c05e8e97e9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:30a678b1132f9d4c60ed478ec7d46f2d942762645d67d4b0b3ded173d98b480c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:2e163c417194c802e04f169af848311ea71ad53eccf8b04e9fe40963e83318e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:282bb60c1c3d2f64f0021807ca07e59971abaa3dd1e8309710c7679cd179d1a7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:5244ed7df7c0020bab6e7a9de81d7a9801af4c3d5d07b529989aaaa3b27abeb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:912328be401fea95735464dc9cf652c0d66d1887b8bb718c881480936c8933ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:03f385bf51f8d6f383543232d870c42ec67482f386c05d6950d0de52921a4a77
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:6c438c3c2c0c5e72a3fa96450912900170011b39ffad6a0915058985b40a2bb5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:93e35eda60bf30a1a959316de81e409f570ebb85b25b2c5b5dc7ad91cb94884c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:f5d482c72ed6371983e598664f0dd45c14e1c3c0572f0273aa3e8c32344903e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:4967cffbf58b3dbae24bf6b2ddaf1a2c1b6bbe37eb18837098d6a27c72c7b4c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:6a81861a91920ae9555cf309d3ce46c0bc3a7044d941374d7185db7cc39699f2