Sign inSign up
OpenCost UI

dhi.io/opencost-ui

OpenCost UI 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.121-debian-fips-dev, 1.121-debian13-fips-dev, 1.121-fips-dev, 1.121.3-debian-fips-dev, 1.121.3-debian13-fips-dev, 1.121.3-fips-dev

Index digest:

sha256:4ce3da7e3d1003e7a50b30e0d5caeadb7cf855db459088ddfbf30d6ffee502ec

Manifest digest:

sha256:a9ebf7f144a98deb51d8cc66e726f198f5489b494e3eef1e4eb599875b5dc45c

Size

29.11 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost-ui:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost-ui:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost-ui@sha256:9f5a4bab70fe57cac4d7779b59ca038c7a3ebc0ea7a6b862c2e6a9b97d9b8aa1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost-ui@sha256:64559bbddf59eb703cf35890f3597dc0433d5f3af8b655e46a9d7ab29dc692ca
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost-ui@sha256:f93fcdd8bcbcd22a57b497ec8fe19eb7bff13f32c3a5944b1c52d168c1d40e16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost-ui@sha256:e5dc5973a297e312ca68d0c0c3460e783d9d742891ef0bd4218d3ab574b67685
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost-ui@sha256:90b92d8919da34756c1d3aab356be6ff834de6ab1580fb032f6cb91dfd79daf2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost-ui@sha256:1cc3f77adf0db19caec70881550c1a6a2006071e48cc9a24d6be77b46278c35c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost-ui@sha256:cb1ffdcbf022a6f2af54c3e20f4311a51209c0bf7402cf9aa420ef8c308bca24
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost-ui@sha256:69283782ea642469df51759e5922a9af8487cae8a2c5407cc03a6745e4048178
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost-ui@sha256:3667eedf1fc24765e60e63a03b4077ea10676fbe04185107eb75d05606cd5790
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost-ui@sha256:444decbf70252251013d03e9e8754b50fd997c3f31681c5d3e9c9206dc7e54c9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost-ui@sha256:e2c236c20d54dbf565e5e7b2f0d379f05854d72c86078851e0818a2ff9233731
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost-ui@sha256:1c837bce8dfcda7617aa31f43bd6647efc15c9cf6eefb9fde13ce64557f812f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost-ui@sha256:8c1885d589a2ebef477210b803e56cbd930373a05178225b139b9ca5ae26e2ca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost-ui@sha256:70d6b5827a7bd19dbecc803977533c59866d5e9c5d99ebea24b745cb798b3070
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost-ui@sha256:0c34b93996977dffb4f8b2ea0c3af6d172ed7ff0142085cb207cb4db2420c6e9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost-ui@sha256:ac8dca2ec5f4743d956518f8b8faa6e4481860501d2c7d4f3ba2411628debf24
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost-ui@sha256:0fec30eddca8a549bb99b12028b9c6dd269b8cb06fcb200d192fa703eb29f52c