dhi.io/opencost-ui
1-debian-dev, 1-debian13-dev, 1-dev, 1.121-debian-dev, 1.121-debian13-dev, 1.121-dev, 1.121.2-debian-dev, 1.121.2-debian13-dev, 1.121.2-dev
sha256:c6f9759339376134cd0ab5cb540d72ce29422192ab01e76790c8ee96426a0d75
Manifest digest:sha256:cae010f7b6f91a4b9ed5dee25fafcdee25677dfbf1a2555bdd3b4815114751ce
Size
28.32 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost-ui:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost-ui:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost-ui@sha256:1f61192b870aca75cdfb2d457bcad517fef2cfeca89ed54f45363bce0f688748 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost-ui@sha256:b51aaa5dcb172bbbc1ff340483981d68713f1bd60ba41c2c5df74fe719f20a8e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost-ui@sha256:af4cdaae984fa35628bf1530c2bc4eb9ce1078fc04b62d5d1001d7a83d1065e1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost-ui@sha256:f2bc010359aa695caa00d66b7c0af1a292703d7f3fae905cf2e25af932fc5c4c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost-ui@sha256:fcadc80f4ad14fcd06b4137915c5bddc5ac2ac62dc9bc37356c2e287fdf6e426 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost-ui@sha256:1598c450ed592c8f36970a5dfd82fd85afb361f92f120f7b31f3a3565279faa7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost-ui@sha256:ea51b88966f1fdaf159c5059fa0f4b6de2c7e6a9495bd204e6ce51c7b31a5d31 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost-ui@sha256:b0fee14ae1db3f8f403de010f3b1674edf8e3bd9d8347f4d0e19286218fdc92f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost-ui@sha256:e10b86ece770aa620e0135d91b95f1f3cd72aba4aed26aaac3a0f0db4318671e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost-ui@sha256:6d9fc9fd1b34f35075761180d6b2b06640ab659550630e50a46c1d26e56cce4f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost-ui@sha256:c8b454c7bf1addef9d5beaac048e4fd7eea19aabfe8826d762f893bb3a6d6343 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost-ui@sha256:f7e119423bb9cc774cfc799b7e3e77acf57051f122eb2ebb910cf42a3b2f26bb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost-ui@sha256:9def2ee225ac01093d995a56a83add92e9790c9f85cf56463fe57992da555ec7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost-ui@sha256:ac62a4348fb33a867d12e774c2e66465123f6335a788e24ee1fcffe13cb96dfa |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost-ui@sha256:ab820bf7b7e9c958705464ba8cbc01161be09254915e1473a2c7d4a530c33a23 |