Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (dev)

CIS
linux/amd64
debian 13
Tags:

21-debian-dev, 21-debian13-dev, 21-dev, 21.3-debian-dev, 21.3-debian13-dev, 21.3-dev, 21.3.0-debian-dev, 21.3.0-debian13-dev, 21.3.0-dev

Index digest:

sha256:7cea167aca1da56b25153975b833d48a287a5f82d107f1c1e79fd5fec5237b6f

Manifest digest:

sha256:2b030f523f8ea14e09f2f42d5e4a1cbdf1e33f2dbb67d266ec740594d3181f32

Size

325.16 MB

Last pushed

13 hours ago

Vulnerabilities

0
3
1
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:6f31fae84647f5235500d9b3d62d029f13e7f7f89f7359ae4ac14c86d74480cd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:36ddbdb3d1224aee9fc6fc5f87a767f2a9b251c2bfe51bb22927e8a72ae412e1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:0f241a67f0261051b179eccfebcb2c493dc78213a6e53c8ccb6c39019630b434
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:d8c80f0faf9226286edb9b6f56ee9d945df574f2eb66e689841b082679c3fb84
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:85b46292d138b0e94f2e1ef4d1dcc17a1711ff8b8e7aa34ef37f61683e27837e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:e8be21e2dc890ceb1d4e0dc795548d1aefe3c4384baa5beaaf075674ff872995
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:0c0a34ab1b748f42757b1d61a744f9cb9593b7c9c3d9a4977a54871e903cddf0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:f73f883c9644ccbff79c723a3be5547c8a8919f06d749628ae6d54a1fa7c03a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:d809e64d4cf51be83bd1372456b2f0dfb90e95ab22b6d02b0eec7c8f7c56c60e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:257cf1432e40911f05bdb68620717b29efee6c68b60c46ce2c75493279eb5f7d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:1a5789dd76b5034facd5305c16750207a8488735ae1330e3322b795e4a9232df
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:75eaafff9c23cc5285fa8f2aad0f541ff3cc64e6de8aa1a59b8048877bae0f88
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:93a7840549722e32269138f13aac276f3e69b73632f3c68811230e3caf5f37a9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:94e31de67c6657b6f96153fe1d59d6021c7eca60d7348dd04e3ad778bdedf6c0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:2cb736bfc884d418908e604a05f44ab5fe2b0dae2ee27b1006fc632c278410c1