Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.121-debian-fips, 1.121-debian13-fips, 1.121-fips, 1.121.3-debian-fips, 1.121.3-debian13-fips, 1.121.3-fips

Index digest:

sha256:ac3817dc1ba3463d56af4ba0a35dfa2403f77aeb2348253d418ed52c7ebc0938

Manifest digest:

sha256:a32fa35a8e8cc3b8ace691d5cce46081f1c998f8b266fd6b9bbdba06e28107da

Size

40.66 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:3d7ca354f7fafde1aa978e8c24546fe94e9cce30c250256e9b36ee3670b0c7ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:8c2abcc3e03fd8010f49cb1c8d89192285353dcf03737fddec926b284ba9331b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost@sha256:b3573c3fa2f63189eabf50c7f560e9ba13f579f170077c855a4519cc6c049478
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:4599f208012d28295adda9aa8f91ce404d971aa1ce1cf59e46fe53c48f9c6a11
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost@sha256:1a5a2be7d5163f1d2314ba15e68b1ac0272debfb0da5e974d357a6e966d000a6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:77827cd83f15fe97a04657bc55a17ae231420c68f5edc1d35717ae5bb91cc2b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:546c4b88814d82a6bda3920f97b2599a0e94b0471edd3b66c961e7e077e93b58
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:f25ff5285e55fa55d2d24020937ab100d18910fbd813dfceb8089014b8e8a25a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:ca9b71dcd2afa61b4f63d0fbb41a4e16becfcda8b0a22f222edb5645c2d95b12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:69fadb25a8580dcdfa3bd3e0258f00e83cbe577acd853aa83435ee5ac1d33be0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:c5d09b2afa244ec463ecdf41df0105529e48b49f552898fe79d705580d6c53cc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:3ba1e241142729dc3cf2aa4c1a3713b53fd89328dbe243f802c859a39565d52b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:91926450c7d35dc0481f0d09fa8cd98a8a4f518930084585b9a889751fe072dd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:e07b31a41002077d860423446e73dc86a725bfffbe06f1df09fa7cf94e5b01f7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:d94487f6bfa304f293f1c8c1ec5ee06718ac9832b5a7b37d8c2fc9dd9ac0f056
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:39241584dec9d8123b23f09b08313fbb3e4b244bad7da4960f353fe65cbb2e49
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:294be5ffa573da0e32c1ad2f359e7ea1d3b6d76a66ab91410016dcfe861c1ba6