Sign inSign up
OpenCost UI

dhi.io/opencost-ui

OpenCost UI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.121-debian-fips, 1.121-debian13-fips, 1.121-fips, 1.121.3-debian-fips, 1.121.3-debian13-fips, 1.121.3-fips

Index digest:

sha256:76880fb60f17e7c647143d82e5c73885c83be2701a656477b7d8481cac7bf760

Manifest digest:

sha256:a0ae670272f52fe504b22c3892b2f437154a0e7b283940b564814c2c426aab6e

Size

18.11 MB

Last pushed

4 days ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost-ui:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost-ui:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost-ui@sha256:fcf7ebf9d90d2227d3860cbd4623b54742f482e87e1d521d04e7452499fc92b0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost-ui@sha256:61b4f2eb79dd6fb3ef7af552b91c1fbebdfe48d680d612ea7be93f61735e4788
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost-ui@sha256:3a2093dafd08a4bc72ac3ffb546e1b2bd496cf7d778bc5b3d7efc256efb7c3d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost-ui@sha256:d87a8b0153c2fb8238fc8d5be88b64767e8a160ec2e469bd66b1a8a9d0563406
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost-ui@sha256:b24f8f39881b2609721cd7117ceb86694a9917828614b6c48db94e6f6fbe3620
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost-ui@sha256:38ade655527480fa090c00eab9cd61a5f6814618b4ccab13c146c7a1540d094f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost-ui@sha256:86bfa60d52ebb90f8b2c477f63466384d709fb4f7974b1e48b4060e786c93653
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost-ui@sha256:9efd1c53aec8a70fd03b32a173333c96f99cd651b6f8b9fda7562a656943a90c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost-ui@sha256:29266a1d45e0d3b9cda0361e60da707c6d0a06be21ead64b96ab96ee2abb4e49
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost-ui@sha256:7b258a3a4afae7594fd35d67a6b40abf375525a20b3da4a245b0d52f0db59912
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost-ui@sha256:0a3996da8b3ceba1a75fae3b90fd02352df76f78c33546904ccdcab5ae8dc1de
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost-ui@sha256:134f5f1638710a2c7a0d2b5423b07eff0836ddbe37ac3b81e2fed438d274bfc9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost-ui@sha256:d4b22ebe981948830adaa85efccf4c75c9b488fce49b6291f237bb187c167b5e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost-ui@sha256:ce6720fd968cb87c27bd0e0dde28a7e250380dcf7e7265cb734cc17ff605e9ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost-ui@sha256:12d6f37b7fca32948dbe094746ab8e9d2523a5615927ac8d4ce5b9cf2e0e7aa7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost-ui@sha256:d3e7a992334be8d0f2710fee75edfd20f4ebe59fdd281179a24db8f57575edfa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost-ui@sha256:36605ce9fdf05cb1227f7779be6d66c5ac2b9f6796f213d0fc221c278020101b