Sign inSign up
OpenCost UI

dhi.io/opencost-ui

OpenCost UI 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.121-debian-fips-dev, 1.121-debian13-fips-dev, 1.121-fips-dev, 1.121.3-debian-fips-dev, 1.121.3-debian13-fips-dev, 1.121.3-fips-dev

Index digest:

sha256:6406578a7af54b21a4f0a99aa913c71c2e118b7fec24a45cf373542f07aed1c5

Manifest digest:

sha256:d1bc19c1e3ed5a5268fdfc52f2e25c393ed4ba4a9acd648584e1d72fb68da055

Size

29.10 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost-ui:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost-ui:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost-ui@sha256:bc7e4b60ff9d7218a4fd5fb1afa43361c2e68f4eb876966bda3596f4f12ead37
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost-ui@sha256:023204263e3c029401220a2537b3c2509e79db7efdf9e41f50076613dec8229f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost-ui@sha256:f645c2456983115588db83bd8166e7062d6654e1594fd5b3d568296d5d622746
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost-ui@sha256:894e84994e5e827eccbc0e6816d26690b723b5f1014699a576cf60d960316a0a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost-ui@sha256:0ba2201d076b2dd80379698e51ea999d3ef5357f4980ad620f33cf066eba688e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost-ui@sha256:a3c5010c7d1c4c8a09bfe0889e4ada95a445559ad502110f09cdeb1927fcc99f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost-ui@sha256:0dc40cea053b516bdd086e054b6367dd5bc01e40ba2aefbddd070ac9f04d2717
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost-ui@sha256:b01da06dfeb7fb1a742862ca587d2b765ad2d4e96c370bd4753664c40d884f5d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost-ui@sha256:f931aaec4402d9a84c0c736ebefea309819a6f2630e9cd0510b638e18cbc52cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost-ui@sha256:98d8a78a6510c192b366bfffe4c7b93b6a4169190185dcb49b8a25e502a9ce33
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost-ui@sha256:06d11a8cf15748b96cfa392ad8c86c91e42a3e4e8b69d58cec1db86b78871a28
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost-ui@sha256:37d1ee8f8439daaba30d3b956097d00c9e27bb976c9b7ac107097422c4457fe1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost-ui@sha256:eed0b1e4574382d2e19781cbbc0ab8f1cf5c5973fd2a2471423637e86573cc48
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost-ui@sha256:c1493bd2216a7a8db7dde9cebd4163973e555ec08a4c2227acf70aca6a5f38e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost-ui@sha256:ff88197017cdfea2ce0a4d3e2dfada67582f243edd4884cb596a3caf4c35d377
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost-ui@sha256:a6b06eb39c11d60b2adb7cc2f271699f8ff2828ed9edc68922d3d8c00425f4b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost-ui@sha256:75af000bea6fe254a6f1588d151da6ac9468f4d01755667282383ab744becee1