Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 20.x (dev)

CIS
linux/amd64
debian 13
Tags:

20-debian-dev, 20-debian13-dev, 20-dev, 20.3-debian-dev, 20.3-debian13-dev, 20.3-dev, 20.3.0-debian-dev, 20.3.0-debian13-dev, 20.3.0-dev

Index digest:

sha256:95a5d2a8d40d718fad069fae6d305fb36267de848fe5c7ef4b1c95615c133ec0

Manifest digest:

sha256:45fc0a82a150913537ad9af00cd66c8bc82accc3365b759331c9ec4e22d62e87

Size

315.34 MB

Last pushed

16 hours ago

Vulnerabilities

2
31
12
28
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:20-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:20-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:550dcc6767ddc4fcecd319401550ac8e09e9775b37f8b43610e44cc4421b9ec1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:f07456e81452795c2dcfa9394a6a719c449ca88300fe5846ff29783daeaedf75
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:240db52e9bdb85da1820d5b4c7f673ec3619afd6421cc1f4ffd9a6fdc5fed70a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:0b0af578e7b059a9db1eac6ddfef6498ee5118f913ca00ff01b0585842528b4c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:d7cc1620a8c86ded2a4ac8bcdbd960fdec54bb24dcab160f79e610e6a982e7bf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:b26a93224b006e952c0c445251362032abebf8eab994001f00b45b5fc59fede9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:0ad0e783a9933b8c6bc2fda6c89f05201d76027f4fbcc662e13fd0cbe4060601
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:06544d53db73475fab138747550efbd990215c22bf6557641a7df6bb0a67edcd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:95015d863936c477f23f45460aeeaf306eff8904e31a3c4fef792e01b363bbe1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:00d5d1505a96d6afd5ea5d51689a4129cb10de34f901bb689a9b061b8d46eab8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:ed2c52f1d8aa2e2c59330914d23a06a05a938fdc524e70d6a10505890dcbe7b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:1c9f2d9287f079d3fea94fef1d8c42bab053b4993e12ec7344cd55ba6e3dec3b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:b6811f0d4c317836243764b55d1b228f931fecc4585e440cf81028717b101b45
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:5fcaa9dad01526f7a3fc4dd64efa41e5d13f5b5d5cc1c1252604b248f33e76f8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:fcaf884b7ef61e150cf832b82715d756ed866c5c0e38c9bbeaa5e0b051860760