dhi.io/opencost-ui
1, 1-debian, 1-debian13, 1.121, 1.121-debian, 1.121-debian13, 1.121.3, 1.121.3-debian, 1.121.3-debian13
sha256:428d230cbe3ba4184fd8926e4d24665e086c8ab018af335c3f75e961378954dc
Manifest digest:sha256:b2791fbe5d0d7feb97de6e03b458b5de73b51a702627fe790d1d3bca095d3b58
Size
15.93 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost-ui:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost-ui:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost-ui@sha256:a4b45f097f59c75c6e7139eb2f97168648c64bc8621f18353523c33acfa76946 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost-ui@sha256:d9a43b1a5ff2fceda927c5d5a85d2f78c8575943f4baa1bbb8d33edf25d4de90 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost-ui@sha256:c54879acb1ce59bf6342af000267c0e84ce0c643cf965b8f96a831c3710198ae |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost-ui@sha256:7a2607c9043034b7bd4c1ed4f3bff15e3cff7c4ca56f169cf9e714a9baa014bb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost-ui@sha256:1ac2b2dc185eb454a246001fa4839ac3fc650e06ce8cdbf7992c83002b4cc81a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost-ui@sha256:7517aaafb43c24fc62df4948aca0344c41145937da04eae75ac5b421f06fcce3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost-ui@sha256:1a45e4e55f72b178c4fe4e09292438b2da0b38b7c5d19c64b492517f4bfe1e34 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost-ui@sha256:7f6ba16c2de8ecd9287777f41d290852fe34b65b1f2ce9782e4a2984bbddae80 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost-ui@sha256:0ba4c1de688c6a8057cff661d8040cc0204b9744dcd0ec2b5c303b49b9307a58 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost-ui@sha256:05707f4b7becb341585e21f533b4b4aec8491b1692234120a02603f0eb4c7132 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost-ui@sha256:db1167d33b6c4a4941f1ae2f3edfdb95de9096c6ba9c7bd0151f07e1cbec2ee5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost-ui@sha256:c9748ee3b355d249b9299da442b005e19af8ed7ddf3d364c597808bcf9ebc8e3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost-ui@sha256:5aa14643b03832f7f902d5979a33733db752bdac7855b3936a72000dbeb5c3e1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost-ui@sha256:38b69fa1925b473fc99838624c17c84dda254b7beb06b64bd04b4654cfb18ff0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost-ui@sha256:a668a6d2e89bb67d8372a5c8e356f412f91a2d94b7a98947c11af2f183b56182 |