dhi.io/opencost
1, 1-debian, 1-debian13, 1.121, 1.121-debian, 1.121-debian13, 1.121.3, 1.121.3-debian, 1.121.3-debian13
sha256:e85bbc07a45b6b2e81e648247ffbd3be64a8eb27925b2e247d39431b496fbc9b
Manifest digest:sha256:a106a37035153136e5c5ed90aee83cb8ab000e7bb4368c729fd043f5f60766e3
Size
40.11 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opencost:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opencost:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opencost@sha256:5efa47a2cb8e24d4384c0371bd977ae6f3988d4b69b28bfe502ddc0d3c2ecae5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opencost@sha256:619a33308115c6165bb23f46bad218e3d62d93f3c4af89357b31bebe551f72bb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opencost@sha256:120325a4954e5c096435e7353240e5c9a9107af23232d8ae5472883237366f96 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opencost@sha256:ef50ec256331c7446a2743f7af6d849a435e865f7953488b59e885dd862c8911 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/opencost@sha256:644c9f5015b4ca0db511b6e3d44ff87f88cc552a824b5717a5d9d67183def96a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opencost@sha256:2357900648ce821bdabcf49f5f6b081c3f8cb366591a150d3bbedb6c09ba3e07 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opencost@sha256:8bd2c1a8a84a9c61fde628d84f443908582076d33a3044d57f2d8e0f3aade6e8 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opencost@sha256:53efae673b28decb6b45069a2a16398f23c1cba37884f8c721099b8f62026585 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opencost@sha256:00080b575e2f73122afc5f590647014cb5b815858c6683bccf3928858ee825fd |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opencost@sha256:e6add5ad6936eb9747e2cc6f59bed7feb5db86234dc21c391716424c77af3a7d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opencost@sha256:a493b6fcf054037d7b182df41611fd42b35a7900bacdfd5a7892bc699e4f54f8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opencost@sha256:527f99975c9f1e2ff571855989c40d49a9d30a7cb46c2409283dce05251f032c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opencost@sha256:3fdf53bd226feb2918f3f40d837b1db2d17028a91a8c63051533e15cdda089e9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opencost@sha256:eb5443a4e6dd1ee3fbe0e65218876bec7b9448716b1dd569e34143748b105b76 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opencost@sha256:5d90f957679563f85b8bfd6212cc1ece058ca54652d58d851a358035e780b484 |