Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 19.x (dev)

CIS
linux/amd64
debian 13
Tags:

19-debian-dev, 19-debian13-dev, 19-dev, 19.2-debian-dev, 19.2-debian13-dev, 19.2-dev, 19.2.5-debian-dev, 19.2.5-debian13-dev, 19.2.5-dev

Index digest:

sha256:e54674c5cd39b8a7b78aaf8a7e1877f641eea5d39f43a5d22255b7f5040e60a5

Manifest digest:

sha256:56da216bd42b48747d60e28f0f778c670008437c4dd503092e556d0b1a289acb

Size

306.02 MB

Last pushed

12 hours ago

Vulnerabilities

4
40
15
33
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:aa8c23b67dfd67fcb2e5683ae6a745edfb255a5c8381f9aeca407ee0d862f7d3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:ba2b7f53bc79b02dbd6d36f476f8d589c5d573a01c4773218a7a4b4f69173989
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:5d6660b9a4d13ba5ef0742d778f2737ca8ad55512fd3f857a0ab82202693b6c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:b5f6c45e14432a71bb0b272a23efe1e68b2ead16df6fb32297c96c5a2f396ce0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:6ebbfacc97b784c31e5cadf0bf6d986270971d787048c9269907b53e812e5465
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:981bdda01f8a2e898712d9899bedcab7fc05594f5a310f809fe5108734136c79
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:b3ec2b925f81dd17f5da6631762009ba72b1e45e5b6b078ba1044bfcb2862d5a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:23b926d30200256c04b8b3317babde14351b2458dfa38d5540f28b5de4871a6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:b165f8407a9a05941243aa69312ccd62928105fe80e36aef45f50342a80e2a12
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:ab9e49fc7b6a09cf7a39b840821766931843e80266a1515ad52ca725a5924123
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:0d5e5a9a5ac39996055fa649a230fd3e480b6cb3877df920ca6d0ae67e2e51e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:b865b90f65e82102a8d99caaec51e2dab18e681e80feb5e806b155441419206d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:c928bff9c4e93ed6663f140ea9b3a8b6ebfa4397c019ba5f6d926a14738eef59
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:8074d9578dd23d3941ed5d09f3795a42418638599897a1664a8ba08cd9d157b0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:203c767e06403ca12da39ae547f7c574d1d2b84049621aeaa9d28a7154be9019