dhi.io/ceph
21-debian-dev, 21-debian13-dev, 21-dev, 21.1-debian-dev, 21.1-debian13-dev, 21.1-dev, 21.1.0-debian-dev, 21.1.0-debian13-dev, 21.1.0-dev
sha256:f41c1d5de058c2efb377856525f90818a0e2b1e5615e2613c4169ca724657ab7
Manifest digest:sha256:2c33609910a8d73838d69ea377b9a82a2ee138a7f7e9c593e41fb18d6374d8ab
Size
326.10 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ceph:21-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ceph:21-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ceph@sha256:85d9cddbd1ab0270ae998d1a409e76309f8fafedd618d952b91669051ede7530 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ceph@sha256:da04324399dbef5259c3731ed6ecd971978ae9670a25cf1746f4739dbb24e85b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ceph@sha256:a89cf805671eae62fae86893aac8fb3d51aa865a7982b27e502811e822783591 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ceph@sha256:89e0241c7154ce03955b7bd040b8e77d95ec44bcb56635d3641adadc1996128a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ceph@sha256:97b96106fca0d6f007519ba5966b260593c8083cd1cf49ff5d67c8cd1d5b7030 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ceph@sha256:5b09d5b2d52c4b6ae5166d407a90693422868b9d0c90e99414b388f73f8fc760 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ceph@sha256:f29606c4cf8fe1ee9fedfbf7efb8effec4cb2466e30425bfd95ac6532627c79a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ceph@sha256:d700cb65931b88b89e8c57236f5ac93549b0b88dabb9b4b8e79a2014dfa21bb6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ceph@sha256:a87fe1cc705112130c96817c97edc8e0f5a17ef6bcd8224bac707845a0d446ce |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ceph@sha256:a0d51530377a1db3ea3726acbbea21fc5a4c191e82fdd3d15eef836efca904cf |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ceph@sha256:c0d9915b38e765c3296baff04d907ddd88aea9dc0161e70c02c716380eaf2e9d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ceph@sha256:0c9287fb60f7253eb2aa518104b10651102d7c9225b3cbfb6c82f3db89ce4993 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ceph@sha256:37248f9392be79a7305c672052f981a7a58f813806f4155e44de07f21d952239 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ceph@sha256:dcd2f8f2e7144962d9071c8c0d4deff6a955b786da266715f8abb89b658fc213 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ceph@sha256:6f4347e8aac1b91aa490506ccbdce8e284e30a3b63448e1b541c963131392c92 |