dhi.io/opencost
1-debian-fips, 1-debian13-fips, 1-fips, 1.121-debian-fips, 1.121-debian13-fips, 1.121-fips, 1.121.3-debian-fips, 1.121.3-debian13-fips, 1.121.3-fips
sha256:204aea53e79d4226a287d8175c336b26fc7b7c71c4cc24e42d87e5ebc09e23fd
Manifest digest:sha256:3077565cea6c8089a4b9ea2a7d0dac502f7cae98617c4ddc013539e3043b5e35
Size
40.64 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost@sha256:9222f80c09d1b4c1db76651f5f7d25eb7c046925d2d91e2bbc9849e145670c39 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost@sha256:6d8c92e540f5d264b5c6534e486a07e83129ace495dd66fb492691f667adad1b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/opencost@sha256:8b238c76190c0cbb1a728b7e04837a023d00df8207d984bc1dfde33ed5932d18 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost@sha256:5955d9e9a3e25d90c9ed0c4d885db145af173cd1cfdb9ce32dbeae175fae8a18 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/opencost@sha256:fcd41426c10929746a168eef14a98c52e1a464b462ab401fb95e429ad057ed4f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost@sha256:2780d12176033b7df0ace66d2cdb0bc5bb52a06c09e7a8d07a8ffee528cf3c86 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost@sha256:e01c65a1f8152667d84c4a1cbc5093c2be842118d2493c2890bc58b50442cc10 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost@sha256:cfb35d9e744f622e7de4b5128dfa7152717031de92006974f2fdf138525dcba0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost@sha256:d5af8520f3c2f2834dd28da108b3818452fe90e87642a9b1d9292b4f25d51638 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost@sha256:6de465459322ecdfc22c466d658b688d52ac1262fb75b7ebb77a1817868dd87e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost@sha256:b8666c708f7b6555e6b05a944baddb3df993725d4822713c8ac96f1fb7a20200 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost@sha256:d74feba59505a2fe3d13e02adb6d873bf09d10c78854a18244da3ffa57345c07 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost@sha256:462748da6389b6979765328b28896ed69140aec0b19dcf9baf8cac65639a4cfb |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost@sha256:c33f89a08ce0a5e02bdac7223fe5e2f725d2513d259ae06c62538acbe7838eb1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost@sha256:fbf69b8b38bd48442ac1a96230a61faa9c6d0d49426fe85d72b888ded2983025 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost@sha256:444d6a6245613748ac5e2517ffba82f3122007abc616eb76dfab44e09dc5283f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost@sha256:0ce4bdd3d1fccf69ee39d0d43ee6a6ba5f53be5f424688bef9aa93b2b012699d |