Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 2.5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.5-debian-fips-dev, 2.5-debian13-fips-dev, 2.5-fips-dev, 2.5.3-debian-fips-dev, 2.5.3-debian13-fips-dev, 2.5.3-fips-dev

Index digest:

sha256:cbf0e88ea4567b268289d48f3705ab900e4fdff584e65a742244cf0aaf42b589

Manifest digest:

sha256:29b99b571aa611a9a19bfdf14b77f1186e736baffcb5aba3612496401f89eddb

Size

72.64 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:6243ee23a10094a6ff1c605b0189e5d6fa1e04034005718603bbede3d346f521
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:55346664f065b83545267fbde0200f6886359240f825c51c012f250cfdbe0ab6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost@sha256:1d221534520c11da41e080053c810d4cdd6c9abb38d54fcb1a90a8e91b1fef55
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:1ccfa3beb8604c6bcc1f42432d14bbe3ba9f197d69c954fe9d74afd5a9ff5312
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost@sha256:88251cca79157e427c46a613dc986a57c1478084303426c150be31ff723ec175
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:3ee25464a52d3f36fac75fa36a68aabefe9027c8c58a9f99fcdcc8447332bb19
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:88c193b6c3fe7ff8d15dc1e7673d0394d3e78c5915f8d444279874a22429f002
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:132efdef8ad75f6d5f44a2a6a98531f019a5b02658000f89ad980d61f724345e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:db4e404ff66a2eb0f9bb71ac2d9458cb181ec24d9de86ed9da6c72ba1e62e91f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:10c179ceab110a9f83986e9c05cf371e22ba86942a57875a7be30174236da132
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:35246dc69cb0560a3c98c507c3012d098796f41d66f77b059062158d20b43088
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:9ffb84b9607e229237d4bc60fcf7d5ca01a80bc3cbc6a37e35d3cbe409e75adb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:7c70ac5fb06f559cc3328c81c4afa73fcd49769e2ef83d68cd7623504663b411
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:edf919e4e640a9fbcdadc7b8d227120106bbbcb6032fd6ff89538e72da1d1640
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:f0282406a136af7ed0e23e8b8027940803c703cd58824968102a89a5d9ffac97
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:7b71710ef010d629314ec91301d3eaf4de302ca17e01bef8585873a1838358cd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:2c534f18bf19fe9de8a86f8d442703300e630e748c77518230970748e9659f55