Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.121, 1.121-debian, 1.121-debian13, 1.121.3, 1.121.3-debian, 1.121.3-debian13

Index digest:

sha256:1e30eb3e4e3ccdaba6aecd14198b636e8a940c764a339b4ed44b91c0a88baf70

Manifest digest:

sha256:654e7f0a9146a9aa32fa036a0b834eef129983767d07a1de2d2cf2e7fa849f25

Size

40.11 MB

Last pushed

5 days ago

Vulnerabilities

0
1
2
9
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:62915f4c30b2468fd405418fe6b311ad0112a2387fdfcc067a86d0d702d6534e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:55ad763d8d6ad9553c6ab128c16abc7f6fc016bfde9fd0ebc5cf61729a4671f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:3be98ae1373453b42880fbe50735bdc2f09863397354a59dac7e47cfef5d9901
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:55fbf78e3ae21da34a5d7689da64617cbe29700b2d22cdf80b43167881479f16
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:54c62bc017da1f3cfab3316f0d6ae02c0a5c04521d061aec0d43ff50637b3431
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:21a99e4b7909a2ab00830361fdf9e43381223dff2068048b5cd70747c051c1ab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:ff82409db2aacd328e772ec1194e0b1e047d5f84cacbe3aa42b4c1827f087b82
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:24305dd43b7cb2ed648ef30a4cf8cfaff33a3b174266b561f58bc75da8a7d0d3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:1ea5ae6cd3940056f3995b3cb23908cbd53f02180cbfb5cbc3007db167aac139
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:99f5f9c44976b97c202d89d952b0e5b3e3c2c35adcb1277e4870db053296bb67
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:cb2f9699ed48d96ca43ebef2d52cc109271b7b897e2391f7d688868785b8bd3b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:8270e7b612746133415ee3b2c7ecb7b18030a5df8b262494e25f24bde79a8ace
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:4d22dad5abbe5db7c5fb968a9740c67ebe202bbbe324f04745038c894c357b68
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:47ccbee8c65620893a8648e791c02a963a3ea065e06da3e5520040954d587bde
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:c3449b52d24d9ef25df7e8bcb4f9828eb1bbb946e2c04b48ac00b762ff66cc43