dhi.io/ceph-csi-operator
1-debian-dev, 1-debian13-dev, 1-dev, 1.0-debian-dev, 1.0-debian13-dev, 1.0-dev, 1.0.5-debian-dev, 1.0.5-debian13-dev, 1.0.5-dev
sha256:3e3c189d747ce3f4b87c4da62c5b25ab230d91d5bac13b8b3f1adb0c47f2f019
Manifest digest:sha256:4d118a293fda1e52280166b9cb1ca2c7625ab082e7b2f27750b43ff072914b67
Size
51.73 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ceph-csi-operator:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ceph-csi-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ceph-csi-operator@sha256:777f07e4c1145cad8427fee1ff03dcea3e23347b79753576e59dd764d4734dcd |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ceph-csi-operator@sha256:9a43181978fea1b8afec3741142a1222f7f87e2f242f665df255238eb1de1751 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ceph-csi-operator@sha256:d00d6fb22e3284c421d6a8fc267a238bfd478ec6468d88080ad9d55495cd5295 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ceph-csi-operator@sha256:1eb9e3674395e944ee4e44985d6b360c65761a6c9785cc636483e5a4ffc272db |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ceph-csi-operator@sha256:992e5ab72977d47e7f1f9e21aeb85bafa0a9e5f8dbd590b80c3918aee892faa6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ceph-csi-operator@sha256:b6b1103072a1beb17c318a051e2b98fd0384846a01b2c40b6c5b4ef9c102ab0c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ceph-csi-operator@sha256:7e81c1e90a03369a831a8d89ac4cd48b2455871b517f68e9b096026294e3235e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ceph-csi-operator@sha256:3d8918f8cf84bfd751680e622900e59519c30d599111e58e86be552c380c9800 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ceph-csi-operator@sha256:9df464cc9b1ab4647e1f1553957ba4fe3bd2e82481b0abbdbbd5701b8e5063f2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ceph-csi-operator@sha256:29f652a178dbf54f762bf23414096e0bb85fec1773ea4fe4c368ae7329d5a333 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ceph-csi-operator@sha256:ff30899824f6361578169ea08d950a92a948bbd48bd3b440c68d099f8e013ad7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ceph-csi-operator@sha256:e166ac5a143bc08d96dd2ccd42f98535c252b6369fbd346d310e03eef4e368ec |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ceph-csi-operator@sha256:9a0395da4be8ce4a88210310162f2205cbf3b2a62bb16bed6fad09e2f276c0b9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ceph-csi-operator@sha256:d969e1382c38028be67fbd28d5a8120239d54fb035d2f37655a19a5a1a4d2602 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ceph-csi-operator@sha256:87236456611b4d32fd72e89379b2168d2c8bce2dfc1563104db91ee50aa59b8d |