Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x

CIS
linux/amd64
debian 13
Tags:

21, 21-debian, 21-debian13, 21.3, 21.3-debian, 21.3-debian13, 21.3.0, 21.3.0-debian, 21.3.0-debian13

Index digest:

sha256:1b7434c94269f6a659d5d1b5ff94a5871427d9c432ff4e6d1200213607270723

Manifest digest:

sha256:9d2f5aa950a152935aa2523c2987a7029bde346bb023b726f11e9a901ac21dea

Size

318.80 MB

Last pushed

18 hours ago

Vulnerabilities

2
31
12
27
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:2f6088d066eec3beb074105840d49b6c1007781e3a8d8c40572789e4a9c6f20c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:da29dbbdf2706d40ce019103c0f0e8ca3c058b0607090c800039ed060f126273
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:385063bb6bf305585127872b49ee0cdb971247a6e9b0b0fe56311aadb56b2dbb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:3e27fd39a5f09b42e8ec108da6b772d35a6b12681b401d72fc9b992db8417d1b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:286cc581a3aa3dfa1d418bf473efaa5981ae5b5a91b8cfd2cf25bc8a15628edc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:b4e865d1ce6c283314566dd0c2b46b1b8019d384d4a50a732f416c4fb5672720
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:895a307b8db72101bbea1c12e101a4c158eae02dd149d4c80f4dac63fc71ae98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:31de0479b8fa83bc763579b65d2876985df5659c6149846d9403dfc0546da477
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:a37a15bcec52416f733b0758eed4b81c0820a79dc41409208fd85cf4cf6a2b74
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:32e84f488169507ca478a924be2b15ae9db248b731e94dc52f79509184c31e19
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:61e564821bb54d1042f72b5643f8a2ea533357319b22f0dbb22fb532ecce4731
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:b66682e180f9258c3a6d6bfd724fd463add3f2477ece0075ea39ba3418e36c23
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:d58abc2fb7b57091edb9e7ab4aac97972c0bdad9ac83a8916893b1b141df4e72
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:5547d24721ecad07ec933d024897b326849f3f8548b8bd4eb6c5f8e334dbb053
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:1bbd0a2b5151d792c5379b813dba8fc86612f4ae52ea518ae1b2e6fd3541d770