Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x

CIS
linux/amd64
debian 13
Tags:

21, 21-debian, 21-debian13, 21.1, 21.1-debian, 21.1-debian13, 21.1.0, 21.1.0-debian, 21.1.0-debian13

Index digest:

sha256:7bff352d7816893f524106e4b42b4aaa49f4abb5377df4ee9d92aa6a747ac1e3

Manifest digest:

sha256:a8eb2ce85a45f1aae56962b0625829aa50c83d0aaa3cadd9642832b56f80331f

Size

319.64 MB

Last pushed

15 hours ago

Vulnerabilities

4
34
9
26
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:0709e9813c98e801342ed95ea21e5fefa0ea5b87ff28dafbc5ece853d8ea8490
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:66dd53c1ca8f3c4de6bc45b48688064d7f7060610dc8522c235020aca9e979dc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:a6a4e2d526c95d48e83cd9267efbeb444eec47fb9277882b578bc8b22162d9e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:1b16108f36b2e42329bd48127114215c0e5057bb050a2b18a0d333ddc0ed7afa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:23c4a0e510a252a0d6cd801bd5aa489660ca446fac2a3086b73c5d824a370a29
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:aa3ea12c4fbe38deec8e7516237859467b2073e161393ac9e326163d5845236c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:5513f094dd52d748a8d8fbc2cc2beb5c669a654fff109ea305b6d1f0f4b367e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:d9f574da83f14189c8a25756a0f4fe0d949637d9ca05071bc1466047958f4726
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:3126414b3794bd7b88b016f14f5e8bd50052ccf8c51b8302fbf84584138dd069
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:072e92ad1dde0385214ef41609e21142eb79c6ece81ae2fcfbef5227c1811441
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:e0e6835d9d485dc3b1a49c91339eef2e027e50590ff0d5ccfc3dda103be29ff6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:6dd1f03f04529f50659da67ece7fec28fa02eaadee0a76898f1de47ae31fe3d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:9f94f28b8bf0777bdc7721abd25ad5d586cc08963fd2b2058c10f99d48f0237e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:df2ad62b4d48d6c5fcd541ca18681dc9f889bdf9dbb868e15c855b5ccacbc906
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:54d01de093c237e75efa8b01b6bebaea96882ab4d3c10591b40a7f1babd1aa5e