dhi.io/opencost
1-debian-dev, 1-debian13-dev, 1-dev, 1.121-debian-dev, 1.121-debian13-dev, 1.121-dev, 1.121.3-debian-dev, 1.121.3-debian13-dev, 1.121.3-dev
sha256:a4217527118908ee1e857495c2303cfb6085c072fb6a593ad34b4344619c563e
Manifest digest:sha256:c202be0fa166f7452a1b7bd17608cd586a4a29aed8fbd99494f6ee6258444f7f
Size
86.73 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost@sha256:bb0833f82b4a9a555c3593f03e681f8d3b663e7f7b669cc80e7d54bf0b28e1f4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost@sha256:4fd73eae221bde922f027bfba943f27f090cb395f80c151550a0964d27f6ca3b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost@sha256:bb1973ff11f71675f3d1b1c18cfda401c1fab3beb129721358c370cf29045660 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost@sha256:9016044ad5aa34b3673364e2ddc961f5d2deb9907739add426e4a06342c07043 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost@sha256:d471603dc440eb937612dd0f757588d7b034344a447865dd3b31970b7e8682b4 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost@sha256:2d6e6f55b028a62edd5a77fad0aa8f377c869bf96074fe2ea13950b699a572ef |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost@sha256:065086561226d662f1e6e250a0cab76290230006dedfd0284c37e880b89338a1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost@sha256:156ad54ad6c37e7050c50e6f75a9e942ac7533c760ed272b956a8f9285619c47 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost@sha256:aee141aa673846bab6f139f4498416b796f1b5a6928900583af92adebf533391 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost@sha256:91fdea726ceebf217c7fc03be20349762b1a92202eb261028c7890bd2effd504 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost@sha256:d82912fd2248920ae4373ad08f53ebdb1e231c72379cd54a6940254f09b1f4fd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost@sha256:48f531aa07f833a30865549096c7a21fce67308d8eb97b79f2a020863f48de31 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost@sha256:b11436f8c41f756ad84dbf91e80cbb5f7acde118ec8e2d932f07acb9ad547e42 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost@sha256:1ed17b59203f00a15f9b00a87424be28faa024eb381bf6481f88ae9bb3849dc1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost@sha256:f918b29442e5431c3085f4e62516c6b21935deb3d57a9feb769e138f9ef823df |