Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.121-debian-dev, 1.121-debian13-dev, 1.121-dev, 1.121.3-debian-dev, 1.121.3-debian13-dev, 1.121.3-dev

Index digest:

sha256:2f441ee56d45996a99beb7d5c4b1ea10e7378a42c16d9cbc1e4aa1a550f27f88

Manifest digest:

sha256:14d3c08ef28921c288a993e6f9872d54d6af20a44503db4de3bbc81f8b0da07b

Size

86.71 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:8129ee74d57b543d30b806014b46c2491c92e337d69c9d0db3887c3731ec712f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:cf7fa009040cbe16f4c372597a5d201666b7d034db1a3ef47bf3f8b69ce8fcd5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:2daa0572f824d0c382de695c1e57b575739a59cfa8678ba58f9e3f952a615296
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:fe7e75960325b16efc77c7fcd785e8023c6e002c5093ac4954bec60e4f59b32d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:584255c6ef8ff0136dd754beab03af662ba2afbbb3a2a7e0e44490a02eceae41
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:79c77f1bf80ce4a0f76cbeef275b3a0b653e01f6dca026add84aebfd8f7b95ba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:02024ffd2309f0aff88648e27b9447d1ee946e9a6c329bccad0d453bf5377eda
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:1ef2fe3b66a1d2ccfaa32535ddf7eca7caf5809f5e5481b6dc6d996e43d26e52
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:6ea54ff62de99c37b9c316137f8775f29a4613ff5f0e819995dfc09051ef4fa9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:1b51cf25fee3c61953a6d1fc7b58e865a5fa4051d836970c419bf0f9f349ec7f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:95f1ad349c35c93bcb9346e0426af7e469ded557b505cc5ff1162e8027678737
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:307673926d5f5a1ef7f63c724710b44a62554c29d198dc4bad4b3fff9c0b0040
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:2862d06e511afd654a2db8aa26c53cf3014ad7a21fce65eeacf1e802acf8d06e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:b572cd391f8d4c1e4ac680e6bb30df7e2d61b4590aa669e68e95695efe351fb2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:446af30c471a3a1419bb0725d8ab3cca3f917119bed4088df454c89d08292a1f