Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 20.x (dev)

CIS
linux/amd64
debian 13
Tags:

20-debian-dev, 20-debian13-dev, 20-dev, 20.3-debian-dev, 20.3-debian13-dev, 20.3-dev, 20.3.0-debian-dev, 20.3.0-debian13-dev, 20.3.0-dev

Index digest:

sha256:28de652ef6f7df228a43a675887eff2682c789982c6dde89a3f2701efcbb3192

Manifest digest:

sha256:81ca7bea4c07d45591fb62e29306f77fcb0a28a806811fce5c5a0750c2e162bb

Size

315.34 MB

Last pushed

5 hours ago

Vulnerabilities

2
31
12
28
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:20-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:20-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:e24a67af1119d1e331ad362a822c53228744f4cb1c445756fa638471f4d35ea7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:1dfd47c5ebd80a956eeac6a401a33b6c99c4e067bae842a651eb70831a1f65bd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:d921f3b5cd739c9f1c5f0f816744645fd8f242383b6e84bbf71fda6f9f8f4d9b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:c5200f06bf91e12115c2d36678c5025af8a40dfd15d8453893f5abcbfc0540b2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:4faf583cba07cef49e6c1db1c74b3c83465fe639be7ec4c7a8193bd120f9a001
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:7c57c08a6d710896a0db8c6cc8d54b2ce4480d2da16d855e161cda0cfb8be5c0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:c880f29e6ff1cd677589f5bf70125ff3cb88894b8447e378aa365e6c67c7d684
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:a18d74f6fdb5df3d40f67328cde3bb7494fb45a7f3f84614b64a530fc86667f5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:37abd2de82b16af551f9909471475b60560bd633a8032c2ec8dd27debffe7e0c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:0f5eb96f26c4932cedcf23716b212a7504312cd809fd74d4e2646d7a15dab1bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:37950f16d5825ea23640afa1618ca8f361a93774c7b6c6dbef9f9cabf01db92c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:867754c3e819de0fe5ce125e55ef8a796990ca73c0fdd946a8a04569fbbf532e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:c2470078a11529c6f79b85807188e4626f129364e946cb3446d769291e3cf883
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:3fcbbca80c4379e339b866d9cfcf64e1bd28a3ca501a933ef5dc1da6d47a1a41
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:a27532ca78deb8565f8a63ad72f155d2c8865fe384142a4b8968c560ca364b5b