Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 2.5.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.5-debian-dev, 2.5-debian13-dev, 2.5-dev, 2.5.3-debian-dev, 2.5.3-debian13-dev, 2.5.3-dev

Index digest:

sha256:aed99b0cc7f2c0151edbb807028803954b8b2652dfb9f84a78480d63b1eea4ed

Manifest digest:

sha256:db7c8bb33eeedf8a617d6060969f236252825489b57f52f877e87ab768253016

Size

71.89 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:61eebbfb867a104b94fc4e94f6c71acbf7f3c41b0da3700cb73a16ac5fa81b10
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:8ba46ead1f69102eb3ab0470c20f40e0eaf67e53ff2cbfb0fa8c3c786e6cc1b3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:5fc5947805c0d006bb6c99811de8fbb1b6d38653007819fbb5affdc844b447a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:b6c58ba97a7924902d1c8ad89958129111884e7dbf0e1f9e5ee0dbdea44e3ab2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:29cae13069075704af927a75ac1bfc7e4f8bf72bbbae0cc45d444d7f1439baf6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:7a98bf93e105c19e0bb93719127d1a7b8ec164e0fa111117cd9196f55faa2002
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:1e4ae20fef96d433148edb597194431dc681c4f9fe38a3d8a4cdcb82e4a221ef
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:d55c305d31d6a91958f6adc6ce5bf85d06652df6ec12e46fec48375b58cc3454
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:14942bb80ce9b1ed67f98b853c39fb1ef237c86d84308ac0283dab4ca0c227f0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:1576a6239c42696e8b4583329860283d4796d9bd015e6f6c91eebb55101ee8f2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:9a65f494ea8ad5b26ae3c1aa5d98dc6862f07d4fbd92141344c317daa5b48fb6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:a6e48d6512980d5d335df49baee4992e6df7459f25c902f2e2eae2beeb209f9a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:4e4c5f70dc5f11defb3fc22a2eb122d70e91e79c73f8a11cd99296941f1e3795
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:cc2dc5df2a2a4bee98ce3c0d1be8d840876d7bc0fa30a2b962f7837192e6ba27
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:3794653f2a4c7ae59078869d940827321ee23cd48eb96ea5512961a615f9b312