Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.121-debian-dev, 1.121-debian13-dev, 1.121-dev, 1.121.3-debian-dev, 1.121.3-debian13-dev, 1.121.3-dev

Index digest:

sha256:a4217527118908ee1e857495c2303cfb6085c072fb6a593ad34b4344619c563e

Manifest digest:

sha256:c202be0fa166f7452a1b7bd17608cd586a4a29aed8fbd99494f6ee6258444f7f

Size

86.73 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:bb0833f82b4a9a555c3593f03e681f8d3b663e7f7b669cc80e7d54bf0b28e1f4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:4fd73eae221bde922f027bfba943f27f090cb395f80c151550a0964d27f6ca3b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:bb1973ff11f71675f3d1b1c18cfda401c1fab3beb129721358c370cf29045660
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:9016044ad5aa34b3673364e2ddc961f5d2deb9907739add426e4a06342c07043
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:d471603dc440eb937612dd0f757588d7b034344a447865dd3b31970b7e8682b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:2d6e6f55b028a62edd5a77fad0aa8f377c869bf96074fe2ea13950b699a572ef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:065086561226d662f1e6e250a0cab76290230006dedfd0284c37e880b89338a1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:156ad54ad6c37e7050c50e6f75a9e942ac7533c760ed272b956a8f9285619c47
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:aee141aa673846bab6f139f4498416b796f1b5a6928900583af92adebf533391
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:91fdea726ceebf217c7fc03be20349762b1a92202eb261028c7890bd2effd504
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:d82912fd2248920ae4373ad08f53ebdb1e231c72379cd54a6940254f09b1f4fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:48f531aa07f833a30865549096c7a21fce67308d8eb97b79f2a020863f48de31
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:b11436f8c41f756ad84dbf91e80cbb5f7acde118ec8e2d932f07acb9ad547e42
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:1ed17b59203f00a15f9b00a87424be28faa024eb381bf6481f88ae9bb3849dc1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:f918b29442e5431c3085f4e62516c6b21935deb3d57a9feb769e138f9ef823df