Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.121-debian-dev, 1.121-debian13-dev, 1.121-dev, 1.121.3-debian-dev, 1.121.3-debian13-dev, 1.121.3-dev

Index digest:

sha256:1df8545259b4563fee12e4423ed82eadd57005cd9549765081513d950c622d94

Manifest digest:

sha256:cf81e2fa4045baa3e04cc01757efbaa85c2ea98444dc865a353a7dac595a3e0e

Size

86.73 MB

Last pushed

17 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:eac749524aa04be53b23d20606e46b9ba26f5a59ef2ecd87b5c18bbb41212f12
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:971b466cb5b05100c99a856664c4e8e9e94484f809d8e29100876e733972bb10
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:4c4da283e235b00c92276802ae262e25e3e36c7b7021b57ab52aa46bcd003f24
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:ae29982a7d1a8f175329c3627fb9bf1094e42d6f10318addff32f2708b0381f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:36d34bf6cf37fce8372cb9af44ae41b5ead083c06a497a117dfaa9eddfd47041
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:6f9c55acaef007052038a88b9a93c37317c6068fb5423e203eab3d96093e9c06
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:9758ea5a1ab6551924afecb7d058d6268e37b5b4c657a022313f0b8192b22fec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:4773744a32e9c6837dc67f354206833f56b64c7d7c0955ee1663424fa2373462
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:225ce1ce8726fb45542ce59494da167df7d7394f0c59b750cdc7779dc1cbc8d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:7e748a631acf34b0b48c0edb2151a67f8a04b42ba4ef87b1830cac22939046b6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:6ff362bc3c8485e1bcf7405da6c99df8780f2db166318315f4f9487e758d2fdd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:8d545e36f1ab1c2c43c6af50f3d5532d1666ff96b7c3746389f28f90fc13fc0e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:8deb537f4b13eacf65aeaf25c0c9b92f649a7a16be35e24d71ae2b852f8b35ca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:29ea5a81dc4711b6441f3580a1aa1b217cd6f70de78acfd6e62cc1d8a65ac78b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:a395df5a1af5b7016ac0143e872c2e37cecc569664fbbf5e71d37ba13bce3525