Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 19.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.2-debian-dev, 19.2-debian13-dev, 19.2-dev, 19.2.5-debian-dev, 19.2.5-debian13-dev, 19.2.5-dev

Index digest:

sha256:dcde1cc1696ca54765ed17e2261c5b89b13f9cd86b325f525633730b57a5c495

Manifest digest:

sha256:39efa8e5fcc067caec501561913ff2b28fa7148feb37d1e199c988b2ce2a9961

Size

306.02 MB

Last pushed

21 hours ago

Vulnerabilities

2
37
19
35
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:666701acc57dcb9be23343d858559df63c2f9ebdc0f0080be4a9d4bdf4725a5f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:ff47cff7d356d1157bb34b86fb6178f716923c41efe30399dd06115c33c83059
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:cf4adbaa85924842b0edfd3d81d660534e93f7bc3c02e3494171a253455d7839
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:4985c22c064e5c2b5dae09581490d67d93638aff15a3057255dd7045f11b431c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:6edb1943fa83c8d9a7576555a2b56c67a43ed319a72c66a5758fadbd7dc55632
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:5537b4ebf6de586a97dfb621442956f2bd02aa30379916ec587a2f81fb5313de
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:9e4135496528a57b8f08f83b5517970b80827bab58912cd4fbf22a52d7407661
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:911743fc23ff78da1e4236ae7c59cf7da4727180ed8d97513f97f31019024c81
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:85004e860b5e17ee8b3f64fd4eae6468ef6132b95057165a46ceb1232a74388d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:17dbe5617128135cdff8465d360e0cfb0fd8b58e39def0cc5f9581cc02e55d66
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:01041f83b66ccd68c799489747c33221cad67deb4ec51c2056b1ab425237e5db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:c9c6e362955e6f78b36dbabb174b859b1c5435c362490af0957d5128224d9221
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:95667e924ade6be21dd62e3b20c5c32d9e0831f136d95e19e51bd92474d6e590
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:ad4728c4094ed66a92b14c568c1a97f651932491c8398997db4ab22177fe2a9e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:0f8b7d10c3000e6fbc2ab39e5328779e91659c83c62f49cb3743ef05d6ecfee9