Sign inSign up
OpenCost UI

dhi.io/opencost-ui

OpenCost UI 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.121, 1.121-debian, 1.121-debian13, 1.121.3, 1.121.3-debian, 1.121.3-debian13

Index digest:

sha256:19a7d8333676087cc5405ff3dc3fa5ea0df414cc1d5f13c66d8e88b698af6047

Manifest digest:

sha256:3f43456a6c23cf96c6391b53c8fccdb4d89d241f27d41d7a74165a672c5de3d4

Size

15.93 MB

Last pushed

4 days ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost-ui:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost-ui:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost-ui@sha256:2aaae08d8102dd11b6096cb54c148fbf3c468a9a94b0eb3138510156be547e80
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost-ui@sha256:9ff448baef498af6b376647c588999fa332c5940ff23abee738501a566362377
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost-ui@sha256:e6f155e485efc6a8f9659bb384bef0563f8c242fdb9c550524a616db011d7284
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost-ui@sha256:4bdff91bb7f5a315c4b53053eeef1d2d3f1426266d80c57c88ae84bebebe911a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost-ui@sha256:4b24986efac12fe1a71326a99618c92c47383401b34ea6c75cd7f9d8750d24ba
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost-ui@sha256:353e48a16e90c4b2851e99d9e1fbe35665f3ae5e29c375c7d141f22ae4648cba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost-ui@sha256:8fb60d0c732683a60b69ea73d37823ffa2c1c3ef632d373fa1214e0afa4c49be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost-ui@sha256:b28d552cf59f862f7f5add405be01e30197801b5cdc1d45d621e9acc42692358
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost-ui@sha256:7033a57dfea68b1122c33c1391a8c6382c7bc10f6eb6746866cfa4c15a1de97b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost-ui@sha256:a6427742ca4bf91d32c9009977bf3e0e9fe3a47125a82c1e50a9ef4f03adf7ab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost-ui@sha256:5af5a3b8230fe4a829384ec68f1fd5b338bcad28435ac7ec69983265058aa861
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost-ui@sha256:9552b182696ce368f411326d7fbf71d2db8435146b46dfeb366d9beeedeb5561
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost-ui@sha256:9acb47f388729f874f654216b28da153d79e3ee47f0652f8eda1bb7baf03e85c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost-ui@sha256:1c6ffef237abbc950733389399221a0389763fbe1ba6c410f95a5ba6fe80838d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost-ui@sha256:ec47cc54125b2ee32bedf9ffb190c27a649c685cb90893f538abd7e800bf8448