Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 2.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.5-debian-fips-dev, 2.5-debian13-fips-dev, 2.5-fips-dev, 2.5.3-debian-fips-dev, 2.5.3-debian13-fips-dev, 2.5.3-fips-dev

Index digest:

sha256:2e6c551d24b178275a55a6437df2c22ecbb66640bc6c076ba986ddc7aabbf269

Manifest digest:

sha256:21a38d2f491b5c932c3ceea41ee3b9aaf292c744891ceff2a1021da6ae1d3a18

Size

72.60 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:794711b494da81b4d237a9e15245baaaaf9ff95beed726237524f1ff419a00ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:4dcd08497a542068d6ed93ecfc93f4149fc7b38e5f5746cce8db7bc2a296b71a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost@sha256:18da31d43cfd19610a694064f6e7ec96aa8b453672f3885164e5d807469d8448
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:163a0f827a21e853db4935cd5cac5264a1a0c98c37ffdfe5d487cf40376b6e8e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost@sha256:e87d03bd0230e349de26512f09d8c812ba056c8af1ad7a472cf9d36339d6f3fc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:f960593196868060066ed922f0cc83af2068090c03c52ecba3107816be87a862
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:407a3f9658dba9d83fc7e82da9855e12208b62fea798530822cff58709626bb0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:fe013ce78b80de36ace4bb244f75e7a57ba62fce19b24bff6be4a90162d0d503
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:203e24f84ac60de2f54b07167608f9d03a3bba5fbc8d13e070de04d5865224a0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:7804c059e2f63d3814df7e0fb34e61cd637b4e69b79569cf85f29d7ff497d761
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:afe64ef9b114b6152c5c34beb8d9f629f018e712e3d44a715471e87f645f4b11
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:f6ae4fd16fbc7606a1eb5b0532cd3eceed464f2e2ee25d96e616c28ab658e308
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:17553ff99e82ea5caf133632c26ce5d51411fde0f837a33b8c956941da74392a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:1b5b44a615d6fa6d44e33ae56841d8dcdd8f7de067ad4c3950c1c3aed436c065
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:e98825160b755769f07d87ea862db88a381ddf1d8bab1635d410e1257c6227ad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:7b105e409e5d3acb625ea347aeffa40a00739795f0e30bb26564aae5b90315dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:550e66a1f14da478ccabe28bf8d3c24d10eccf98ccaaef01461c9c74f989cdd1