Sign inSign up
OpenCost UI

dhi.io/opencost-ui

OpenCost UI 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.121-debian-fips, 1.121-debian13-fips, 1.121-fips, 1.121.3-debian-fips, 1.121.3-debian13-fips, 1.121.3-fips

Index digest:

sha256:3445bbddb9a39ab759373a40b00cc33bf336ede62af388382b9637c62867f01c

Manifest digest:

sha256:856e85e8d7e58f5e33bbae26ee5ade9b6b72d3a44f642d0b0c958d90924cb43e

Size

18.11 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost-ui:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost-ui:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost-ui@sha256:db5580631e5d95b1d9bf379e01360b70d338fcddb80cd6c8f4c336b0ed3ccdd3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost-ui@sha256:2a79f19ab7ef2d2ed31968f7d3a7af2704e78ec9cac871f767463237e05b0176
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost-ui@sha256:e424462b78d2c8e298ab0803f6f7126288c80ec9525123c0519d7ac233eaf813
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost-ui@sha256:7fd6a8b8e76206da6706715b5d007991e5d01d1d281e51225971f9623de428c2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost-ui@sha256:585361d48fcf0182c89d2c22cab2cf3f8e1b7511a14978f147d3e459e7c9540a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost-ui@sha256:7ca308d783755246e6d91788921c73317f5685b038db40a4d806c08691388206
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost-ui@sha256:014f6489e573ad6d409d4cde1a2fc296cf532b83af2fe08cc287a8d2276543a3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost-ui@sha256:455e9f764860975888e1ab03bc9c2395b4836d3c081ae5baa5549491e8b8348f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost-ui@sha256:25f2ed38ef6400f10eca9a2ee6b2bf2a17113b5d348683263d99ab5d0e1de8bf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost-ui@sha256:96d23c9bafd431e7947a8c24fe1c6ac1f03993104d74d941682de74e10e788c5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost-ui@sha256:5f16d2e007763fbca5ddc8238176ce79fd468f0557d9fe3f11950830e3d802a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost-ui@sha256:22f9784ef6919e57242d4d6a6e6e3072b531e85c8002204ecddbf4c2c851de85
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost-ui@sha256:19a5c5a205400edf659fd2b9fd2f56b651b1364c5bbc9ab174a7891d77627ad7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost-ui@sha256:c8d2be8e2568fde0bf408eaa8225c378d9a908c40b9b2e1bcd604690c37eee1a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost-ui@sha256:e07fdd1933cb307a280e224f06be1ec20bbe31f32520c5da3260b66d1eaa71cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost-ui@sha256:dbd8d65af3e21ee8273890afb1f2a3a056dd05b95c751f17b530c6760e9ee722
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost-ui@sha256:6c7e5aeccd07d45a4d61fb47ae8c423715e5e4e49da840b6694843e0ba67fc31