Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 2.5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.5-debian-fips, 2.5-debian13-fips, 2.5-fips, 2.5.3-debian-fips, 2.5.3-debian13-fips, 2.5.3-fips

Index digest:

sha256:ba781564d073510755ab9cc975a07da0bedbd15729b1a179e530542ffe62821b

Manifest digest:

sha256:0f59c7eb4e7e31dce2c673f55c71eee14da83a8fed76fe2347bd8b05ffcae42a

Size

33.84 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:8e32d8568ed7cedef0c124d8aa50c58100697e84ad8be616f282d71d07ad06ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:7defaa0373ded39f042b933fd208407c0c992b6d8a8df55a4cdec9b50ec00970
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost@sha256:1d0f29f05c21f460698c7891578820f491946c0307251cda86d158b9d342a854
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:908351b7d14dd6ed23a06fc50fbc43aecebfd80ea6f7e48913e3ec1bb12662cd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost@sha256:75b5bbb2e805fbfe7a2a72918b00d07172b007078c46a8c32b2748ad3a43caa5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:ee89042344cc48d4425cb9ede2e1fcda1ac0c5d7d57b60ab00b28bcb63261eab
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:d7165457619d80fda0700f8b8ee2e7612a8a85a97146e844751bbd9225e7f603
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:2858c32688e8ffd88c7485ef150f5b2e1dde6eaafe32e3fb1fee4a7036c1a9ca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:98718e8e63082caf4e11f24f6611d23652d267366efd0e8120d548b74f0e1936
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:9ec085cfc05adb63bcdc588a96e28bff328d603b1f54f1dfbe3f155815e94c93
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:bef43ed23cacdeb18279284a0c0c04c139f75d08893d5395b5a3123e51b3c17b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:134a62ed551edd1b7c6fac4443f80d2bdf730d2f21f9e3857c9b9927c12c5169
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:00b4355f8aade8c0534f5a67d6f2d305acd5a4dd4b138b93f21879d39c95bb9f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:be730faa6c3643374ad402d7ebdb9291dbef19a0d313fe57c5a3408c450eb068
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:0375fecca27e3dcc3b10f1a93a08659b7d27d48632eaf147c6912bfe372af804
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:d4352baa016be32b991726978eb84c5774af7b599d95f835e12525629e200761
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:dd7baa8d9dfdaa2f34b2d64ba44d75b1b7ebe9e8006cf443cab6308a64a11d50