Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.121-debian-fips-dev, 1.121-debian13-fips-dev, 1.121-fips-dev, 1.121.3-debian-fips-dev, 1.121.3-debian13-fips-dev, 1.121.3-fips-dev

Index digest:

sha256:5ad95a04ed45b3437f0c153cdaac5d197b992fcc55f7ead193d2a10ea0bc7fc1

Manifest digest:

sha256:2de4b735aa6cc5f14386e188849876e6bfe9e60e9c8a7aa7c5a1f185e179f2bc

Size

87.49 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:bdc1191352b6eb1c929d37020628b9881da029b9a554de6dfa623f5d913a26df
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:e6dad4c9c87c45e74ff93c0f65a4304d54ce8282c3bac436c0ffa8a1c9569740
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost@sha256:57d6b56e9a33ab5eb2a3c81f6af30033b4b27f33d9243996048e469db1fb6846
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:8e5a82767f58d0f462e4651b357ddeb5f159dedee5fc16f5cc68ae6f884d6c2d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost@sha256:f6a2dcc61597d156384a02d9e960ffbdcc72deaef3c62c07d97ad896dd9f0644
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:a206597c4478fcc8d2a7ca84bbb13fe75dbe877112b337e0be03902d3024a85c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:d3d6abcdd4453e8053755beac2544533c1c7230c8d3d4450ff6ea385bcf91b82
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:19849107e28ac04d459e41e5a68a7456ce9a1fdfe0b6f32d20ecc1e8c717b8c2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:48dc21ddf5a83cd83a5bb9ddeea22e753b0427375c907646c56cee3ed5baf59d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:b7681930d3e15e9e318688f0178e28aee05173ec1af50dd9a00ad2f86deae39a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:653418481a6bc6c9b0b6427b4e84a86000392e7db0afc129e72964c98cf37202
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:5837217322aef098fe742913333aa373bcca58f3abfdf2ac1fcdae04576cec4e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:dfa538914549a1977c0a52902a9dc02028a03b1eeeab2c273f90978e450f8860
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:57e6b595e330136e288265cc555e798a2c978c592d95a311476bddf94c9af8db
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:c8dc0b2249a6f68d782ec34078af602c9a78343fc4937b5fb9a6ddb6f464a469
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:05095aeabb0436722f0448d4857a580a9b6c059f53f2b0f0425c98d1a3b09d67
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:e6c25c461af1f770ab18537d6fb778704b003cac8be0cb481a1c989f78264e16