Sign inSign up
OpenCost UI

dhi.io/opencost-ui

OpenCost UI 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.121-debian-dev, 1.121-debian13-dev, 1.121-dev, 1.121.3-debian-dev, 1.121.3-debian13-dev, 1.121.3-dev

Index digest:

sha256:f044968607f73a4d30ada9324ec67bf387c59227f014306ef435fe07b74668a7

Manifest digest:

sha256:120b031aac88aaf1dc17382c3017eb4fcb698e24aa3463f3ddb6282b6c6047a2

Size

28.35 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost-ui:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost-ui:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost-ui@sha256:ef0aab825cff8c42de111960db7368a101257184d503ebf7b58bb4580a2b0d93
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost-ui@sha256:7293d12005d95c1ab84866f2b068ce5542a0d1e1ba09d4c4bc564804cbf6d022
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost-ui@sha256:6dabe364408ab5a47e070adefe45f89fb2f5d8993cbafb76cb7ff221a8b5ba29
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost-ui@sha256:303fdd7799e3de8c64fd85964a5be141c4660f3a3a812fa100d1096c52c88bd7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost-ui@sha256:45d0bb2d48bac5b07d277c6f3e532014b309edf32fa11f61bcd11c45f5a2f98c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost-ui@sha256:a5b7eef324d76ec5132c29cc529b4e2c59328d491d650259220cacfb33ef3d82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost-ui@sha256:06df8bc45fd008dbf5d7c4e5c75935bec3d14dc356356a7a3d434361f0afa51a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost-ui@sha256:80ba8307944771fd9a6391803bef0b9aef9f1f47e94de2357a0ed27115ca4fb4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost-ui@sha256:1660b474ee7ed248505cc8e0fcf595862679c357d14cacab70e4e7902e978cb7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost-ui@sha256:d7c6f0e8efd87875be42e774d008f8daa034fbb4320543329daec0934e293e75
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost-ui@sha256:f7c5cf1b93a10d92f200b37c07b9814554d70fc86a27cd7d3b690cd6bb496bfe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost-ui@sha256:336e9068142cb045f0434e6aaa36f6ef3115ab749e3421c2dbdc33f4bcf21642
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost-ui@sha256:2d236c67dcac985432a2a61e71a1d8ca750d7bb61d0134ad302be4508399238b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost-ui@sha256:9113cee71cda2d4e6f909e5f6ff87142f6b934969443ca19e5797175733787dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost-ui@sha256:2ff38d6927f834f8bc3c448bfad177377d7c0949fbedf81d5589ff2fe7d71efb