Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.121-debian-dev, 1.121-debian13-dev, 1.121-dev, 1.121.3-debian-dev, 1.121.3-debian13-dev, 1.121.3-dev

Index digest:

sha256:4c5820f888a6f7d618175ae050729f947466c7c8f878fd6d96fe8821b2d7d6fc

Manifest digest:

sha256:de9bf4c6dc2b320722a256765319586d946f99f39c753d90232e2ecc8322bf82

Size

86.73 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:108765024aa99f914bee8d9126d4ad92e4ed466dba7272dee33866dae9b8a497
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:1f303be7be8fce9b8343cc074f13849e8302cab89d9c5be933556688224ef6d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:1b0d5a6027fe8c021b27c4d320225af2b31ba679038c78da5a81bb024452bc29
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:ef2ecdc383f0e9e108321da59417858763cb9cd723b07bb7728630467820b8a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:5ef0db7b7f4205a368e35f5ab6dd6815680c16da96c2c86441a93296bcae584f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:6bf22cf8d1f30140d29372b87d5afefb64dc6f7789531661523427a5bc8d47d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:a30123571246c73670f6bed15d9bc487e00300b3ffca616a3a2e84cda5e11b07
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:4a3bd21a30f01e772660b470c6d77d0f18ccaa1c7b157304952b455d0b9d2e0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:5ad50eac3415cb8b2779dc9cc73bc9e80bc58c8847ec8f2564e763edd5b83d00
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:90ca2912ad515762c432cff9c19049d7db10750765eae132754a2f7e83924139
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:e8ff5b1011dfbc8cd07450bf23b1e6e5e61a178763ba3f1b413ecbb9ac13e9e3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:b51e73899bae6ae12a7a71fa89e16b94d1148531da655e934761df45af185de5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:acc80d2b63b2de48b866a756bc700f594e7c14636b368ada1d17073c904cd701
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:5e6583bafcd6522c669aa35837185d906a8fc9e7a276a39155e4215a85d30d13
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:d790ce767e53cf67698dc8879c7cb1c0ac112e8fad014a269beecc5b14a27d33