Sign inSign up
OpenCost UI

dhi.io/opencost-ui

OpenCost UI 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.121-debian-fips-dev, 1.121-debian13-fips-dev, 1.121-fips-dev, 1.121.2-debian-fips-dev, 1.121.2-debian13-fips-dev, 1.121.2-fips-dev

Index digest:

sha256:83a647a9b56f552bc84d1e958c9998a7c2ca91893ab6610379f5ff8897f0278a

Manifest digest:

sha256:bcda536b126ec72bdee2605e1f1bf765611f6863d395e0f548db30ddf60e7d7d

Size

29.09 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost-ui:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost-ui:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost-ui@sha256:22ad9b1abe82ef18e50839d48320b8e7270adbb13fac75f0895e5b784f141876
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost-ui@sha256:ef39643454341b1387d0baba16e364dd757d927623a5e5926fc790d4220f45d8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opencost-ui@sha256:1eb582847d7a93f3a5bcf39de98692095485b57bb8bd2adf4bddf20edc913e6a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost-ui@sha256:1a7f0fca053b8bbfa13b3235833f3967d0a93b61d352ef25949154c5ac90dd00
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opencost-ui@sha256:5f9b596c59a08be3d4d3dc5b2032786296afdfb20b9e7abe6a304385c50ee185
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost-ui@sha256:4be15d3f30e3dcd2961a060bb586a7b99375ab60752455c06835031ce3113552
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost-ui@sha256:a8f263b5180328cac04b75e6492b57a939855785e4ef843b76640c942902ac9b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost-ui@sha256:dbdd08935fc1d77b25c67b4c8b34710f414ed497282edd0032e4ad2ee8e91ae7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost-ui@sha256:47c8f22423b2eae3afa05adde9fa883ec3f5f8f179610398ea6c9b3631e59bc7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost-ui@sha256:f2754b448d5c5149c4bb042c16bf4b8b863ce9eabf7cb9a4f0660a74109b45a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost-ui@sha256:6b01f9773fa8c69f6f055ce1658aa3044f46f99f03853a5ada4863c5dbc01402
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost-ui@sha256:f97f5226ee6c0bc0575282a5d87a44fa4056d38c66fb7ca873383f1a36942538
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost-ui@sha256:c99331d548cb6af50b9e679fc1426ac324d9e09ebf49d8c7dd8f772c3636b2a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost-ui@sha256:4b834d2f68ea28091d30042e88d3c97056f92045ac74db4fd740fd83238e7045
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost-ui@sha256:06072b38bbb90af181289123fc778653f9ab28be0406fdd31f78394cb06f46ac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost-ui@sha256:f1268b0519b6e72cc63413c82d48608a6567007e44c176926051858eee1a0996
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost-ui@sha256:2c6f203f91b2edb184c5139dc6da28432f94c2cb410f63a87d66323e73b8430f