Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 2.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.5-debian-dev, 2.5-debian13-dev, 2.5-dev, 2.5.3-debian-dev, 2.5.3-debian13-dev, 2.5.3-dev

Index digest:

sha256:d0bb2b9208352ffc9a33db3181c52d0f9027039bf52a635206f99d7568d1617d

Manifest digest:

sha256:d57332ed130f3182c21fb86f75cdc33c164a3fd58ec6b6a962fd0b666ee63b5c

Size

71.85 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:77b4d491c017fd953c19aaa365aebc5277a7ed9193b3ce463517451686e9e8a8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:b14ab10cfeb39c974a9170978f6d3e8e836e433b9285172449afe40719da88ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:6cd301f4df17cd09092a14dc394851352b6bbe2ed3fffb698d452266ee63e3f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:2610bdd7a8f8e02d9db81d92eba117df20d336b4fcf37a2419ee9f7bd774c916
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:ecfe903afa04f86ae566981e3a0a53cd0752ca3a3102ca1e4c59543b982ebc35
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:ee1ea2b05b9bf9a91ad0f490f091d32ad88c2fae6db8c913b8c3ec13ef64f359
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:268240ceeb15544414a95fc898c6f0886b4f1b063a282722eede85b1c1d346ec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:7ddbceee708ddadc91c37350c6d9c7832d300cf0f934840f37c901e389044d11
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:edaf69c384b660bb7afba80b392e981a3865e3058bc97ba4e4335d063b01911d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:52e61bdbc1036f78bf7f632f1197f671582492b237bffad096b3ea7cefc0f27a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:f80dd6226a86121f68cdd4bd192df5d5b79b413010cf83552edc8c186e5de16e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:7ab893d659dd9708cca5382610978d0d5435f9319f17b4e27018d8d45aa03fa0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:708ee532159a0a2c9ec7280df0e3bb7295f4b4663f77ac526eec1c9420f79229
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:0ca6f2748635d2ed63b1e46c86a08cbec54c0de7921f64e83399dadd63cf06ab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:ad7d080b784438b32d5e3d40814de7d930acacb9917bae9d38bf9287c227ecfa