dhi.io/opencost-ui
1, 1-debian, 1-debian13, 1.121, 1.121-debian, 1.121-debian13, 1.121.3, 1.121.3-debian, 1.121.3-debian13
sha256:19a7d8333676087cc5405ff3dc3fa5ea0df414cc1d5f13c66d8e88b698af6047
Manifest digest:sha256:3f43456a6c23cf96c6391b53c8fccdb4d89d241f27d41d7a74165a672c5de3d4
Size
15.93 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost-ui:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost-ui:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost-ui@sha256:2aaae08d8102dd11b6096cb54c148fbf3c468a9a94b0eb3138510156be547e80 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost-ui@sha256:9ff448baef498af6b376647c588999fa332c5940ff23abee738501a566362377 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost-ui@sha256:e6f155e485efc6a8f9659bb384bef0563f8c242fdb9c550524a616db011d7284 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost-ui@sha256:4bdff91bb7f5a315c4b53053eeef1d2d3f1426266d80c57c88ae84bebebe911a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost-ui@sha256:4b24986efac12fe1a71326a99618c92c47383401b34ea6c75cd7f9d8750d24ba |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost-ui@sha256:353e48a16e90c4b2851e99d9e1fbe35665f3ae5e29c375c7d141f22ae4648cba |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost-ui@sha256:8fb60d0c732683a60b69ea73d37823ffa2c1c3ef632d373fa1214e0afa4c49be |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost-ui@sha256:b28d552cf59f862f7f5add405be01e30197801b5cdc1d45d621e9acc42692358 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost-ui@sha256:7033a57dfea68b1122c33c1391a8c6382c7bc10f6eb6746866cfa4c15a1de97b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost-ui@sha256:a6427742ca4bf91d32c9009977bf3e0e9fe3a47125a82c1e50a9ef4f03adf7ab |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost-ui@sha256:5af5a3b8230fe4a829384ec68f1fd5b338bcad28435ac7ec69983265058aa861 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost-ui@sha256:9552b182696ce368f411326d7fbf71d2db8435146b46dfeb366d9beeedeb5561 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost-ui@sha256:9acb47f388729f874f654216b28da153d79e3ee47f0652f8eda1bb7baf03e85c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost-ui@sha256:1c6ffef237abbc950733389399221a0389763fbe1ba6c410f95a5ba6fe80838d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost-ui@sha256:ec47cc54125b2ee32bedf9ffb190c27a649c685cb90893f538abd7e800bf8448 |