Sign inSign up
Ceph CSI Operator

dhi.io/ceph-csi-operator

Ceph CSI Operator 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.0, 1.0-debian, 1.0-debian13, 1.0.5, 1.0.5-debian, 1.0.5-debian13

Index digest:

sha256:bb26d27a22edef683d792fd20a4095b8b4dc1ae6b1a58a828a9c13a786f52791

Manifest digest:

sha256:afeac2a5b04cd87375b1171a27fdf9e7fb220a53899a7f1a165b33a00c477a60

Size

14.87 MB

Last pushed

17 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph-csi-operator:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph-csi-operator:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph-csi-operator@sha256:a48a0f4f863e974eace827ef3cb80afb1f1c720ff7356009440b501f60da52f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph-csi-operator@sha256:8c83f985c2866918b2c5b9bbd303eb0a465287a150d091cb685f8d6b3838b68c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph-csi-operator@sha256:6dc5bc415033459df9ea183f69734518327b3de01669a7c31c21a430d9ba01e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph-csi-operator@sha256:2d97e2748f4c8bd602e67f6ebfd1713ef7ca013cd20fafa6204866e75566c126
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph-csi-operator@sha256:fd89d785a1e18f2765e5bc420ba023016a944c1f1a4817e2294d6667712b63d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph-csi-operator@sha256:35bfdb0d73fb2dc57ebb3a6c6a426b26536e5e845b2c0fde32abbc32767866be
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph-csi-operator@sha256:3ad3ae9edf34c1712b38252b310f39d69cb9ccc0ef9114dd96f0e8fd9f895535
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph-csi-operator@sha256:9d71be5ab1c79cecacf629d09ee15bbfe50a4abfb6b5b696864ccb6e501c8359
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph-csi-operator@sha256:1c216b24fd8445c5f522d4d2d90afd8387ecbc8af4ad4a99be242edd5bfeccb6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph-csi-operator@sha256:e38af6d732d9cdc09b8640bcd4ad83d6804797071965b1138d3d2bc20adbb848
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph-csi-operator@sha256:b71f75888729f44dbd8bbea9017700b7d8b3c68de6d4a9680323a7f82d8e2538
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph-csi-operator@sha256:ef7236f7c38fe5bb9dc6a3890825ade075eea9003f91a1d1f2d5dd892ca0a0de
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph-csi-operator@sha256:b36e179dc5a59dd6331cea4b174839e6800535176cc7c200db80075bf6afa0c0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph-csi-operator@sha256:013a0b1faf1bfa85514005648c0e24cc6cbaa08d8e9d686b41da24e64cbdd196