Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x

CIS
linux/amd64
debian 13
Tags:

21, 21-debian, 21-debian13, 21.1, 21.1-debian, 21.1-debian13, 21.1.0, 21.1.0-debian, 21.1.0-debian13

Index digest:

sha256:7bea16bddc33169a99b32face5bc4a2e299d37a80182a8f57a97a164e7d332a6

Manifest digest:

sha256:d545f168ead79e2dc48206c39d76de8d12d4fd3caa1dc0c570c8999b9259f635

Size

319.68 MB

Last pushed

11 hours ago

Vulnerabilities

2
30
9
26
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:99abdb3492f7850d2f33f6715aa2c8a16f7bc91d0166d7c7bc45d4d7f9b10904
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:79a6ca0c35121ef02589deb22dbf7cefb13975ed7aff954c953419a0f4be10b2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:4e90370aff73d8914d45003cc89900714646c84edc4cb56722d79865b7ed2f0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:fc07ba1f01f1ff16633f1a9f4d04125ca97f4216b20075b2b0fb32955c0a82cf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:eb80b55812d7cec1bbc11e3feed664df4caefded18bf89e1a431fb9781e32bbc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:e7bb65e2d44941efc859889dc62ea489c5940ab7e70f1cbbf1687b0d77e7de11
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:8d3704404c7298d03789a5ed13a03d84ca4572fc59e237bf6d25265b007a80db
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:cc5323b59d30abb1b5cf4254ffecf0991d5d4d592f6be649169c99941f6c441b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:64472ac4b7745460ca812ffe8ca7f9da4f5a59a35d5c53d3e1f3ae427f37ba03
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:116e50910107f483cc0f082ad21a8a425cf8501220c40787915777718e64d417
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:cfe6b71c695cdcd5dabcf04089a10fe308ba802d24f4032cfeb579dfca57bfd1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:bc0cbb6f51aca71e9d1870a3a3fd5233d89ae0a10fe0d4cf909eb2904077a86b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:3e43f64613c7999cf69593f403004d7986de5778a952c07edf12e3d571d47ad4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:52a5d751a24057e86dc630a033bf13f37b2435b29237bb8e852f0bf3614ebc1f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:782127ba9d83082232acccbe9c1e45efd8e445d3cab333ef0bfa317567c49577