Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 20.x

CIS
linux/amd64
debian 13
Tags:

20, 20-debian, 20-debian13, 20.3, 20.3-debian, 20.3-debian13, 20.3.0, 20.3.0-debian, 20.3.0-debian13

Index digest:

sha256:d7e9e9649f4edaec4cccb98b292a2d939b13fa2cc0e8bac96377eb2379aad9e1

Manifest digest:

sha256:65f271c6b1941d682555bf3efd079144d2c6cfc2594ea5bda3d9ffbb7825bdfa

Size

308.97 MB

Last pushed

1 day ago

Vulnerabilities

2
32
9
26
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:20

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:20 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:7b98fa3d1f3758dcad9ac4f73e2f76d7e9cf3964aa010095db85c177105a0d89
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:fa74ffecb7c17a67fdf16326e1adec7021831d42dc962f2d678818972aac14d7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:1bbdd8e341ebf9a648d66fb4915ec1959b22b1503e50cb0990b0c13e71f97b2e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:1d0324e620baf076fa4a11e4796b984165d4dcd2d9f317325be218c526e4927a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:46b6bd462a52b4b10c30dac27cdc0ea1026722e47cd7652de15347e49c1d52aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:d1d228bb7e4c43f1f5755355a0eea2fd6fb1528393d27073117b4b1fd29b9bcf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:702c0124113aad1fd371fb431de3109b6caa7d1bb147b45bbf159faacf977faa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:4a0b16c3c56ccec9c9a2e9607600f8a7ebda026cbd6e166c2389046545098b99
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:39e38c8521d97fb5534079785b7641eff43e64ac53545937376b3ad6dfaf4122
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:cbe5fa4157b9741ae6bcd73660f52a77c025a11c88075e888132d82e0610a0cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:5af8eca8f4a931813501cf82ba4890e155a67aad2d227ce9ffdf565527365b9b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:e25a6700e029712a8c0fcc109f3fb4da5ec369fb4ac03d16cf24123eeabb3ff9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:ac53ee656117cf16682ffd54714d967dd85346c7ff7be9e0fb6ffcf0808394dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:c05513fca8d4a66772f07e8647d6f94f566b7c091b1fb45486fa40ce6d18afc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:ef8d029882112a14c1deb84d8e61e57169da7d026ce3efe6e58cebd24a57fca6