Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.121-debian-fips, 1.121-debian13-fips, 1.121-fips, 1.121.2-debian-fips, 1.121.2-debian13-fips, 1.121.2-fips

Index digest:

sha256:9e69863304fdb0bb504b811a335bfaedf4e817255cad3cadc46f0961b0e6a07d

Manifest digest:

sha256:893bba3f66370899c2b85eed4f19c07c49a5a47696720c365018cb24086974ce

Size

40.30 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:9fa038a39bd1ac01dfee17a64c7865271281c10212e7840b40685b2de689c1f5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:b2731562a39b357f8fd106a9b6b658c5b3c95510360758d6e81ed13ae71ab16f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost@sha256:ff53dba2967fd64e438d108d1a8a3923507c8fac43f4b68d247433378bc22cab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:74646799284acb2e2323f0e955e9e7d0515f5d4416dd0f6514cad1741c5191f4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost@sha256:179af09511d7a98d1ae761de95229add69ec73f4dd79b072c6e63b334ad042de
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:f44684c30599c760df8850b609481b7ce85d05a22f533650ff7c45c95e6af8af
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:0b0e3d4f66bc3dde19d22823ae56a21744311973d4a78f2feec6a6d071e95aa2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:bbfa823c7bbe280fb6fac4e656f199d75881dc0e6faa3068c75391f447d3950f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:b33601b2965f03f6c9b32695f1335380b5fb18745db29a987574c08908cde716
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:1e8b1b6416e4d7960cd5b5657cdf1527b1bf340ad13e4c08ba7ecbb7fb55163d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:1d2565f9ecb1cea4a60134639f02f76c46f9c28f5e987e8a246a398d9a4daba2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:eb6f0eb20680768d22dcc725dc22bcd146044f674bd4139e20befe8e3489d63b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:34437bd7a55b3030b093c8ed9b47de88d3c4a6b3e2f3ef1470f6dbe1fb883660
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:24657e39e5b8bd195d6f74cdd8b057535786184489fdb09fcffa80b608c91635
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:f944a84557815500253a727eac3175c5f3e9eda2fb2bdeb1262f0e759b68ad08
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:9476035166de3e78d3fb7e3e1c06c55054a39bbb24648aa978800ebe599675a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:f887ce0d7719f1767a7bec3f148808031b0304da36cac94b517b14692f62f9b5