Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (dev)

CIS
linux/amd64
debian 13
Tags:

21-debian-dev, 21-debian13-dev, 21-dev, 21.1-debian-dev, 21.1-debian13-dev, 21.1-dev, 21.1.0-debian-dev, 21.1.0-debian13-dev, 21.1.0-dev

Index digest:

sha256:68ea65dbf331105017707a07eccfaa9aa89c84a03ab1ae38060bf60d3fd6f37b

Manifest digest:

sha256:7513b55187eb76ef6c32bcb9f2bf93c6fb42ac9dc7fbc4da441dd7f2cd1d7421

Size

326.12 MB

Last pushed

10 hours ago

Vulnerabilities

2
30
9
27
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:71d54ffb1f15a1c4e3bcab62e9d090df99903410cdcde95f0c8c1acc6eb96a65
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:9634deaa2870b9bf3cea990c115a1cdcc49904e76533676228d97b5c89002517
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:f6db7059555272c8e7d2337bb5306e938c59eec9ad4c28bc14a7f61d8ff718f5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:a86ea0f75c99528a3f44262b1a65b2f7d0c12dd05665f7461731ec811a4260cf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:b28c61de5f2c33843b03e933ba80b00c7c501457530eeeb8710e62f093c1d048
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:6d64771c03e651356fcfa3f6bc240b7f13dffb4437717a9027cc2f77a9e1f339
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:34423acccd24d4a06957fd466895a4b1157a15410bc76953b488715f7e9ae6bc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:8ab796ebd5a2efa08bd3ef1e987e3cca0ec737ac23f30986ecc96f83096f7baf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:9dfd80ba64a34bdd48d049393bc3d0f843db253e2bcb57f4894342f28eff1945
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:4e061b64578eb827d9b50d2ec098ce2c4ffce824bcc94c2cc4a74abb258771a0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:426ed8316ba47c55d8013c3bb98b65cb0b366566144da528760c3eda972df6b1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:39470cb88b0e00fea77bfc1046376142e24041d96b3ced0f9ae4f87a0bf6eb27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:f9173c06a3df04de17ecd7122cf05fdac604d5485e6c3b2431b0fe339a012063
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:ca2190231d8458746b2d7460494d4ab041b11968ef3585d263120bacfff35982
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:6a1500ba8e84dc6323147069e67f675a74c6376c5d2f611132b4e58cfb7b0720