Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 19.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.2, 19.2-debian, 19.2-debian13, 19.2.5, 19.2.5-debian, 19.2.5-debian13

Index digest:

sha256:9b2bd8f282b45a8e1bedcabb10c3ea695da3c07092a52f900b4206feb0802aad

Manifest digest:

sha256:1b65d5d49a83b19c0d7982262e1833f7daec965b75b1a17b964dbeda1ce462bf

Size

299.72 MB

Last pushed

22 hours ago

Vulnerabilities

4
40
15
32
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:6c67951150006fcb28c5d705109a6ef1039c08ec94172cb51ef36417ec40987a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:981b6b2070855f64fbbda2b0a316938726328f920eac4d934982b650cfce8285
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:e74db43cc74261e98c23522475af0153406aabac27aa835dc68dc20e5bc964f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:a01558a6d6998b40845d5b852e653523ce712033e9cfd92cd3af97de0bbcb8bc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:70992c6d81feafb61a42694dd9ad78afe3151acfcccd6137b78d65668bcf0161
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:f6a386b8a45a106a7f7dcc348572f3e48fe416bee6a932bb44c7e201acc81763
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:aca2b5d12b58cb89d1f56dc45f626ba1309ea4f1915ddf5777092f156b82c50b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:6068bb2181ffc9f74ff6db2a536c04c65fc8a80f4e1f1f94411aa973d5092316
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:68f7939ab7bbc67e191c2c3ea96f2f367b2d5f316ed5609311e5abbfbbc9328d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:281503dff2d218bd7971502588047ada5e9ebcfd5433e4d6dc4270001c5940ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:f91b9806e490a368b18b3d6ffddad4c26f2fa90a39dcb30b5fc2d7e602f989bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:6e9bc17751b6b8625c22d2f2d1947311d2d8959e0133a5c3b21e2285b9dc9211
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:d32aadf2b96a33d380e00c85495dd64fda976d02ce0b04c2d3e2055ef6bd218b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:c0e0f877d3c2862dea6293dd8ffd996b39d147d8acda87e21b6ed48e862ba489
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:4151be3c1ba8efb9ca5aa250b10b8725bc8e40c5923d6496ab80d790597eff8e