Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 20.x (dev)

CIS
linux/amd64
debian 13
Tags:

20-debian-dev, 20-debian13-dev, 20-dev, 20.2-debian-dev, 20.2-debian13-dev, 20.2-dev, 20.2.3-debian-dev, 20.2.3-debian13-dev, 20.2.3-dev

Index digest:

sha256:d17937030f904613bdb5a24283f72f939fa4b06ddefbc929ca34834e8c3bbcba

Manifest digest:

sha256:4d9e92518c4361dc093b8698cba24b23ca6923b75a50d74b53e21a754d689eaf

Size

318.00 MB

Last pushed

12 hours ago

Vulnerabilities

2
30
9
27
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:20-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:20-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:7fec309b7317315a5458c422161506ff4590ee813fa9c1778d024b3157debc8a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:4dc39b27895032838c0abdd9a590d2797795c4ff51b9f666d3e77c3c92a774b6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:1fa5238171cb21dac187d4836af8df14a427335932b886bbf63efabc669bc1c8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:f5cedc126909281cfa017462ae44d418056af67a4346a12cb90ca94dc1781feb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:72a792f034c9fbd0f905e856c60fd981aae6ad1360a26505bceacde75d7dd2d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:31c001422e0cc102a874f18f9bf494d92a1f8a30ed49b632f5a155d552466c08
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:1411d4f40936aa311515eaa7dd96a8deefa57400344f53e4bb0efc45d4f11573
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:00dbbdc13dfa3d39b1065a026d220ccf3bebcd2c7b72a9205d1adf36ca152c0d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:b0e2b4dd9405a6bf81dee65ac1dfde347feb569db035d1b9a2bb1e9b7318dc93
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:1f6cf95ab117b6f913c0dd2611b81791624a4fe547212b4147b805069c59d442
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:7e1d827ae676d5c0a31113cc67e7b1933d066e0b8e2266e4c4175a89664cabbf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:a6ed3422f2009019b1f4d42a6bd7c47986d32b8b4254141ef21b126196119d1d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:10153a46d4ff889ce6820b713dcfe2be36959fff3c80197d0c333fd4cf28dbe3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:41648852589ae4b26333f7e9b9159acfb4773e6c8e0bcfbc5b6719f2b01bc51f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:41a9e6041ca1f943fbbd195f0b5d0a8b85ca8f9e439ee37d15580d41cc1253ef