dhi.io/ceph
20, 20-debian, 20-debian13, 20.2, 20.2-debian, 20.2-debian13, 20.2.3, 20.2.3-debian, 20.2.3-debian13
sha256:61c3ca0860028fd061123881b31e7f4968092ddba9b9c8e182a7c8406121f4ea
Manifest digest:sha256:1cdd1902bf900575e244a42e6ab0fe6a269d85a6077d7a2f621f0c1d4bd37abb
Size
311.56 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ceph:202. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ceph:20 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ceph@sha256:dbab354c74ebe9bf12f5af666c79d42887459d521efcc8f13fd40d567bd7c144 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ceph@sha256:ffcfddae24e84d3130a729cf2b25495f3fe987d5b4c9d06b97f03616fccbf555 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ceph@sha256:e8ee19b676454aa50e271bfca319ef0d187aa76e0d11c68b814ebad333348cd4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ceph@sha256:0dbfb36258466a25e442fe78a9f20983fa7e168be9575e91c2e90b9b8b6263ad |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ceph@sha256:6d4f67b70164bdd253484fff240e668393002048602eab3b4f0b5050cd24a4f8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ceph@sha256:2964ffec8dd843dd4e9a5448cd83e74c8c4e11fb2fea58b38c678f3d8ddd9526 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ceph@sha256:dc72264cef51812c4c5883f22894966841052e6e39fb5d2ccee6f2ea09e6f787 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ceph@sha256:c9240b359eb3db95fde39e7de67dbe443f8f59aa49a3ae6c77dd3c4f2348984a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ceph@sha256:47f10ed24ada30965f88de69b599a008728610527fe84ef63916f27a6281b116 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ceph@sha256:4688fca19000df0f9a0988c58a3b99b53118ec25fe4dfeb2762b4a269d8ac114 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ceph@sha256:0da73b10f1ef6a44e97cbb907a2457a1523bb5a1241ef9cd84c675bb2bff6fbb |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ceph@sha256:ca2f897fafe79972248cd8fc8089fca9bf0292604fb828e795062c75519abebf |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ceph@sha256:de9e03d4feddd0ba9a557f09146286cdc5174b7f8794923423de372e87c0ba44 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ceph@sha256:42618ed6e63eeeee743fec09b9ff0759032de65f916d4f3fbea664ba4897ceea |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ceph@sha256:9725723fcc27fe07cc01f30707a893ab0ac8c5f4c44c29b9c4fac97dcdcca48a |