Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 20.x

CIS
linux/amd64
debian 13
Tags:

20, 20-debian, 20-debian13, 20.2, 20.2-debian, 20.2-debian13, 20.2.3, 20.2.3-debian, 20.2.3-debian13

Index digest:

sha256:a288a98d366d336c50d65106691d20b7d28cfd8f713cb1566aa06c62a3b6ef11

Manifest digest:

sha256:cb24ba7dc203c3c2bf220e370855b9164f472fc6588dd2a4ec32f9ab0ffaa87e

Size

311.57 MB

Last pushed

15 hours ago

Vulnerabilities

2
31
9
26
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:20

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:20 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:c1d02f9edcdb82e97ff449ebdeabdcb9b339c564d7a88a86f8851c9fa544c68d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:93d3d3068e2463b7b0d894195ceef73074f537d20df056d359d9c5b7348624e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:7f8d9db2b6aa38fee1dd67b99c0df6d8dd7eb076ca92b76e21f14b4d6492b0ab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:ba7137f69a4dfa86a63d9f3f117e4c3f7e82889d067f342ff9d4e0ee107e2118
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:bb6c77d0561333c7268a67c30a80c213ba018f527ae9b9d93d451da22ef2a12a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:7de79c6cdcb55358e16414a8609b8f82f1a02d79ffcc3cf5420c2cbfb7c034dd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:849788e53e712e680df0cde0b2e1f043dcd3dd839dc92610d5d5cb8b5ea0fa15
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:0bde42ce776ca4231f90118658edc5048ac22aeeefa4e5abacef44b6da3d4642
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:6e43dd0bcde3e1167722fbb38059f491f89f41a59df47aa8eeecf764cc1fb14d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:74cd2fda6ecf7dedeeae6f71f9a8f89a2169bcf5fc0e69db11498d215ae4a4ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:320a85bc41dec99b14cb11930a1b9d5943b9b0385dd4022ba950dbbf808df652
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:a805cd5624263d1583ab7a863b12c025641b1962f27ead671583ccc496833b92
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:42c78e97f84e52ad1ff1241f0af32dfe9f7df193450f772eca2197414b8164c3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:5704e720763db1691d1cd36037b4d73b2d7039663df00d141a43efe3be9f4d5b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:b6aafc6de93715c33304a5f592f161a47d5b7c25955c4635bd4a99b9889d535c