dhi.io/opencost
1-debian-dev, 1-debian13-dev, 1-dev, 1.121-debian-dev, 1.121-debian13-dev, 1.121-dev, 1.121.3-debian-dev, 1.121.3-debian13-dev, 1.121.3-dev
sha256:2f441ee56d45996a99beb7d5c4b1ea10e7378a42c16d9cbc1e4aa1a550f27f88
Manifest digest:sha256:14d3c08ef28921c288a993e6f9872d54d6af20a44503db4de3bbc81f8b0da07b
Size
86.71 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost@sha256:8129ee74d57b543d30b806014b46c2491c92e337d69c9d0db3887c3731ec712f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost@sha256:cf7fa009040cbe16f4c372597a5d201666b7d034db1a3ef47bf3f8b69ce8fcd5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost@sha256:2daa0572f824d0c382de695c1e57b575739a59cfa8678ba58f9e3f952a615296 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost@sha256:fe7e75960325b16efc77c7fcd785e8023c6e002c5093ac4954bec60e4f59b32d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost@sha256:584255c6ef8ff0136dd754beab03af662ba2afbbb3a2a7e0e44490a02eceae41 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost@sha256:79c77f1bf80ce4a0f76cbeef275b3a0b653e01f6dca026add84aebfd8f7b95ba |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost@sha256:02024ffd2309f0aff88648e27b9447d1ee946e9a6c329bccad0d453bf5377eda |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost@sha256:1ef2fe3b66a1d2ccfaa32535ddf7eca7caf5809f5e5481b6dc6d996e43d26e52 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost@sha256:6ea54ff62de99c37b9c316137f8775f29a4613ff5f0e819995dfc09051ef4fa9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost@sha256:1b51cf25fee3c61953a6d1fc7b58e865a5fa4051d836970c419bf0f9f349ec7f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost@sha256:95f1ad349c35c93bcb9346e0426af7e469ded557b505cc5ff1162e8027678737 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost@sha256:307673926d5f5a1ef7f63c724710b44a62554c29d198dc4bad4b3fff9c0b0040 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost@sha256:2862d06e511afd654a2db8aa26c53cf3014ad7a21fce65eeacf1e802acf8d06e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost@sha256:b572cd391f8d4c1e4ac680e6bb30df7e2d61b4590aa669e68e95695efe351fb2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost@sha256:446af30c471a3a1419bb0725d8ab3cca3f917119bed4088df454c89d08292a1f |