Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (dev)

CIS
linux/amd64
debian 13
Tags:

21-debian-dev, 21-debian13-dev, 21-dev, 21.1-debian-dev, 21.1-debian13-dev, 21.1-dev, 21.1.0-debian-dev, 21.1.0-debian13-dev, 21.1.0-dev

Index digest:

sha256:810411dd8fe91ea5a3eabda08584b805548d14fb70d0b2ffeb69682ab371472c

Manifest digest:

sha256:47840bd02febfce133c54b82b9df6c8d6a036b571faf06eaa1825a5170d14cc4

Size

326.12 MB

Last pushed

18 hours ago

Vulnerabilities

2
31
9
27
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:2652bcd64a7ae290738e3cce02662768b5df05811e97f3aba93e81d738d457cb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:c68a150e78e936d2856c36487f8fbb6adf9464f137a56c0b17fd734acd5782d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:b5479f48d46a660c4beb170e085a3fb085dea082b737fbf269afce1a8e6ed955
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:1e2681d0dcf2e915dccd8244c68b3fa24cb3af4e6f18510dd115a8d1d1152e09
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:b04db4e9e894df1effa1c3bf5b7a6e4df4a386c3819037be2c34a6f5ce92f5f9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:486d8f8bfac395b7afd1712bc0e5a58c631c2dc4c3ffb520b7923155544e832d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:985aa8fed91ff2b7e641068269f00bd7b3dfc380a497e5206c70bbdce5d0909c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:a99aa48f7d574eb207999a7f5531b0f295318203f202b1d0db18d09cd2e65a07
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:06bb8c31ce921d39af5097a50159e400bee3bf3f25da492a243a12eecd4c3069
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:57e484b16ba7ad1483508de05ebf6b19f7606d31d4ea003473d529dc49e86de4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:0e3a0ac051da2f8edcccde4ecc3d82c3ef8ec753b4ca57ee81116a8a9f4d47c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:34321ab9f3acba0ecf9d636e3bbfc7447b8f251ee5bf4b36e03770eb6af91223
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:98abd7631182e60e39ca9899965730f5d9d3dd3a66cb7e50490bbb76ce9d1160
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:04cbfb536a3532ee9f5469f2668c80b8df8eeaa265eb26f3b968d26cc3b1d445
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:9f69255efd8c7cd7fbca05750b1b0914d1964ced8f370feade5b8a270286a424