dhi.io/opencost-ui
1-debian-fips, 1-debian13-fips, 1-fips, 1.121-debian-fips, 1.121-debian13-fips, 1.121-fips, 1.121.3-debian-fips, 1.121.3-debian13-fips, 1.121.3-fips
sha256:e002a56994aa5c98e4931ae6e6dee8b2085807d685c6b4aa605fb44956a17d5e
Manifest digest:sha256:191e2418fd24b3316ca899af4372aa8b87e109b4f86915ede5eaeb4f41d49b7a
Size
18.11 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost-ui:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost-ui:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost-ui@sha256:799c848f36931251c498863538ffa512022c86fa039d32a305ee75e07778a53d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost-ui@sha256:1132bbdff33ba6f05ce2e9d36a09dc6c723d38228b3c0827cf2c595b52cb2898 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/opencost-ui@sha256:43f1cb51ddbfeaf0a3553dc8068569fa1dc4659a50604f42b67024b398a4fb54 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost-ui@sha256:d17780324d086d63c12ca7e7580bd31a2fcf9f35fbb40d97eada770ca2172935 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/opencost-ui@sha256:64bd4003cd9424a0491e8e5b2864f1f4601156f478a1e49926c956e27bc7602d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost-ui@sha256:52d055e75380d6bedcf32165c006bd562dddfa2bc0b42c0bfee6c9a4e4c8c6c3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost-ui@sha256:badf2e204fab3ecefa17d459809ff4b2dce97a0c97afd66f641ed6e531c86b75 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost-ui@sha256:63fc1161e5d9b194b691fade315e5f561b3751a0d3f1c73f2913e0f091f2d1bd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost-ui@sha256:48851bdc35879599dceef259235878330b5938bc2b958f14a4936d0a5c76dbbe |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost-ui@sha256:8031ed65308b8ebf692761b1bc5c915c8dd72db18aa2465a865fbf3f1cde6a3c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost-ui@sha256:22a82d294a89da200d6579abd8b4db4f365a3675e62e1ad4c6a70599424ce8cf |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost-ui@sha256:4f2cac7f7420fe133440c3d25acc02954df79afaae23ec9ba349b90799239f74 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost-ui@sha256:f8abc23f20740d4b8f1f3730de8db866bb087c242af9d0d48601129024b69635 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost-ui@sha256:beacff36cc40a2d2870593b2a2555c3fc69f8b9d115af90f3eb75f1d3f7a7df2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost-ui@sha256:f6245bd9dcc274adf273c9008c654fb7d5bfa3f095e5c67c52d7fcbca9ed3579 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost-ui@sha256:f6c6894714bc9cd0247fcd22d13971651fa9fd8a5adaf62a6f84fac38ec61e80 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost-ui@sha256:cae1d740e1587320ceb51bb10381d4023b57ce9de9162d2183df6c24b9df6d96 |