Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 1.121.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.121-debian-fips-dev, 1.121-debian13-fips-dev, 1.121-fips-dev, 1.121.3-debian-fips-dev, 1.121.3-debian13-fips-dev, 1.121.3-fips-dev

Index digest:

sha256:9e6f9d21035ec640c70a40daef78dd29dc550cfc7d595c0a06675a4a9aa6ea89

Manifest digest:

sha256:280bfafc643758dcc1a822f34441a41cd2cf8835555c7dd9759106f6aff517e0

Size

87.44 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:8a909b6332e8a8b12c23a06e1d939bc55839d63c264e184a5b1ead3c5cbd27f0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:6c03a0db860a63e5b354b1ccc0da5af347bc5a9672780a7c95cb22a860c1676f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost@sha256:cfc20f8d252d5a7966bd350d43676c84cd99aa8fff93adbaaf6277809e71fe99
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:334fa75392b5472fa761740e1d8bd11bdb3d1337af9c377d86a6fd36437c371c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost@sha256:f189aa9802f3286cc4c68195a00fd73a073b55dfdafcb0ba168ae070150ba13e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:59647057bc6d12dea36f13dae9832c24eb1080ced8fbced6b2be51852ca25bcc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:ac5d1ffa32f2ec07224ee138bf3719a38775ca8bd56785644df36ed1301c5258
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:6fb14c3c9dfd93dd33095ae710d9ad78365b8111401c082138b155cabebb8579
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:9b57c30a80c559d78351afd14bdfb7ecade1b8803dccb98000ae545b7161d11c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:472f43b2ea2fb9029f6a33c6ec3c115f37374731b6d85443339a9c1ed1d306c7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:5540901e4d6345a69fae0b58a49b9d517f88d39ec6582c4cfb4113d2b4c27759
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:c4c86920cb5bc54d14f945886b5e5273b260d1befa99bcc681710d0339d60809
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:43cd4fbab35a59c8834e9c6e488f1d66dfe9e3495d7722f109db37e28f1f855a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:66a699ec8142f91a4ca7f0990896122daaa9edba396b08d61aec0e946bc8bc04
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:dd1b76ee25108c1877bd8413df1f9b2ca3aa3e7637728b4d6ad8814198576880
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:81bab472f3fb455e4a25709c3261c1d27ff5003f4be501d6d4e6241700f4a8e7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:bff6084032111e86f54dcd1bd44b94166f91147517e2fc52f785de5f7a67f139