Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 20.x (dev)

CIS
linux/amd64
debian 13
Tags:

20-debian-dev, 20-debian13-dev, 20-dev, 20.3-debian-dev, 20.3-debian13-dev, 20.3-dev, 20.3.0-debian-dev, 20.3.0-debian13-dev, 20.3.0-dev

Index digest:

sha256:ba370bb0823e26be3e14da9085f0eb6b83575be9f9fa355ea9d9c18edcdeda2b

Manifest digest:

sha256:7641251e73edaa5986251e9872260f1c106b48d87a8355d58b4fd18e097b0634

Size

315.25 MB

Last pushed

12 hours ago

Vulnerabilities

0
3
1
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:20-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:20-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:8f60dca566ec190494c8b8cc9b9a7622cf7072b15cbc2b7caf0497708ba2c6d0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:4ee023966dd0aba98e6f2d126974cfc85f24b1467420d52438fc6cbc1918a6cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:7aae6138e69fcb5169252098227f825c69b1a28edfd55c7c742222a88ea5c4f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:8d5caee3d0bd97432a020a74e48709e8d2be225bc684c6fdbddd3209d23a4066
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:a9dea05702b4edfb131d9e9b7df472ea337f8e3a9b31b5d3e202912a44f4e92c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:af12abf857be01237c6fc9092d7b5bc5bcd246f348d3cd1283c14f129551f475
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:f6944757bdeb752c8a74a427913ff119240dcba619f7b3d62da34fb5f4ab251b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:2d330ebadfc80fb97d9eace3cea1e34b0383b466a91fe25771c716fe286724b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:cdf9c6e056bebd98a4039ff9307853b3c73039f5d96ddd7d4d5c5ee831f201b6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:b6fa5a884727092ea9dac982fc28d653452ab1dd1932a10d714d954c1d4900e2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:66b9891b72838076328faf10a68975a3d4022dd60c22128623ce3980ba38af0a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:54bedd9a8a31bd8f51e3e9e0922f2a99e21e36fc18f933fe4e34b1266fa8b315
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:b5c703bb69f8323cec6b6aae559e489dc73db324a0ab43cc0b69057811a363ab
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:95fa2df20ce532f2cca5a080f95c4d1b425dfc894ae6aceb17b114d127736637
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:2d058b5642042fc0aa905dcaa653306d54496d972cbcbb663a8b6977adfbd8ae