dhi.io/opencost-ui
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.121-debian-fips-dev, 1.121-debian13-fips-dev, 1.121-fips-dev, 1.121.2-debian-fips-dev, 1.121.2-debian13-fips-dev, 1.121.2-fips-dev
sha256:83a647a9b56f552bc84d1e958c9998a7c2ca91893ab6610379f5ff8897f0278a
Manifest digest:sha256:bcda536b126ec72bdee2605e1f1bf765611f6863d395e0f548db30ddf60e7d7d
Size
29.09 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost-ui:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost-ui:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost-ui@sha256:22ad9b1abe82ef18e50839d48320b8e7270adbb13fac75f0895e5b784f141876 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost-ui@sha256:ef39643454341b1387d0baba16e364dd757d927623a5e5926fc790d4220f45d8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/opencost-ui@sha256:1eb582847d7a93f3a5bcf39de98692095485b57bb8bd2adf4bddf20edc913e6a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost-ui@sha256:1a7f0fca053b8bbfa13b3235833f3967d0a93b61d352ef25949154c5ac90dd00 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/opencost-ui@sha256:5f9b596c59a08be3d4d3dc5b2032786296afdfb20b9e7abe6a304385c50ee185 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost-ui@sha256:4be15d3f30e3dcd2961a060bb586a7b99375ab60752455c06835031ce3113552 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost-ui@sha256:a8f263b5180328cac04b75e6492b57a939855785e4ef843b76640c942902ac9b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost-ui@sha256:dbdd08935fc1d77b25c67b4c8b34710f414ed497282edd0032e4ad2ee8e91ae7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost-ui@sha256:47c8f22423b2eae3afa05adde9fa883ec3f5f8f179610398ea6c9b3631e59bc7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost-ui@sha256:f2754b448d5c5149c4bb042c16bf4b8b863ce9eabf7cb9a4f0660a74109b45a1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost-ui@sha256:6b01f9773fa8c69f6f055ce1658aa3044f46f99f03853a5ada4863c5dbc01402 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost-ui@sha256:f97f5226ee6c0bc0575282a5d87a44fa4056d38c66fb7ca873383f1a36942538 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost-ui@sha256:c99331d548cb6af50b9e679fc1426ac324d9e09ebf49d8c7dd8f772c3636b2a8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost-ui@sha256:4b834d2f68ea28091d30042e88d3c97056f92045ac74db4fd740fd83238e7045 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost-ui@sha256:06072b38bbb90af181289123fc778653f9ab28be0406fdd31f78394cb06f46ac |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost-ui@sha256:f1268b0519b6e72cc63413c82d48608a6567007e44c176926051858eee1a0996 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost-ui@sha256:2c6f203f91b2edb184c5139dc6da28432f94c2cb410f63a87d66323e73b8430f |