dhi.io/opencost-ui
1-debian-fips, 1-debian13-fips, 1-fips, 1.121-debian-fips, 1.121-debian13-fips, 1.121-fips, 1.121.3-debian-fips, 1.121.3-debian13-fips, 1.121.3-fips
sha256:76880fb60f17e7c647143d82e5c73885c83be2701a656477b7d8481cac7bf760
Manifest digest:sha256:a0ae670272f52fe504b22c3892b2f437154a0e7b283940b564814c2c426aab6e
Size
18.11 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost-ui:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost-ui:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost-ui@sha256:fcf7ebf9d90d2227d3860cbd4623b54742f482e87e1d521d04e7452499fc92b0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost-ui@sha256:61b4f2eb79dd6fb3ef7af552b91c1fbebdfe48d680d612ea7be93f61735e4788 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/opencost-ui@sha256:3a2093dafd08a4bc72ac3ffb546e1b2bd496cf7d778bc5b3d7efc256efb7c3d8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost-ui@sha256:d87a8b0153c2fb8238fc8d5be88b64767e8a160ec2e469bd66b1a8a9d0563406 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/opencost-ui@sha256:b24f8f39881b2609721cd7117ceb86694a9917828614b6c48db94e6f6fbe3620 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost-ui@sha256:38ade655527480fa090c00eab9cd61a5f6814618b4ccab13c146c7a1540d094f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost-ui@sha256:86bfa60d52ebb90f8b2c477f63466384d709fb4f7974b1e48b4060e786c93653 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost-ui@sha256:9efd1c53aec8a70fd03b32a173333c96f99cd651b6f8b9fda7562a656943a90c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost-ui@sha256:29266a1d45e0d3b9cda0361e60da707c6d0a06be21ead64b96ab96ee2abb4e49 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost-ui@sha256:7b258a3a4afae7594fd35d67a6b40abf375525a20b3da4a245b0d52f0db59912 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost-ui@sha256:0a3996da8b3ceba1a75fae3b90fd02352df76f78c33546904ccdcab5ae8dc1de |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost-ui@sha256:134f5f1638710a2c7a0d2b5423b07eff0836ddbe37ac3b81e2fed438d274bfc9 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost-ui@sha256:d4b22ebe981948830adaa85efccf4c75c9b488fce49b6291f237bb187c167b5e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost-ui@sha256:ce6720fd968cb87c27bd0e0dde28a7e250380dcf7e7265cb734cc17ff605e9ad |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost-ui@sha256:12d6f37b7fca32948dbe094746ab8e9d2523a5615927ac8d4ce5b9cf2e0e7aa7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost-ui@sha256:d3e7a992334be8d0f2710fee75edfd20f4ebe59fdd281179a24db8f57575edfa |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost-ui@sha256:36605ce9fdf05cb1227f7779be6d66c5ac2b9f6796f213d0fc221c278020101b |