Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.17.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.17-debian-dev, 3.17-debian13-dev, 3.17-dev, 3.17.1-debian-dev, 3.17.1-debian13-dev, 3.17.1-dev

Index digest:

sha256:ccdc9e660815a606a57b1664f2304e57d7afef45e9929713d2e4da6bf7c685dc

Manifest digest:

sha256:477c163f77509521f18c9eee94c4cc703330a8efe4bf6b2f1f9f35c8081cb78b

Size

144.88 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:b0254398825da9581f57f498bc2ea53fbf6383ee74f2e3f9c8bdef7fe8098a77
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:e61b82cb8f27f736d43de5c3a301f097c9c8c66d469e1b236f5645fb26e066fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:fa84b56bfb13769f367dbef3bcf0d79ba7f338c28454b62ba65e7f5769be53e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:dc482d8cf26cb689a34d9319c686220e52ed2ceee20d4251018cdd180cb6b39c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:932e5bc89e34ddecc1a8855b3b01837bcdd4439f2a97662a35c09a256067edec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:3b658d629da5ce70b2a9595a772da9b1b8b1a19089648e74c7343ad85932cb74
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:948dfdadfcb7e0a992161caa841c48b6c26a09b5ff25bf1e17197711bad0d079
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:c6bd4e561467d7e70f2441be2d70908d860364866e253f67dc65ff9bc83a2a0d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:e2f95cc50b4f064ab658db69e4177db7c9d896680281e6f2a9ac893e34c4e8a7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:bbfa07af7697bf87a89ba0ca08daaafbf9c65c85f2cad97566c79cbe2351765b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:031eb03e4d85ea232234ede7c23ec031e6ed1f0d6f7ff7f53a4676a5331cd9ee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:93e6ef13b0e328806e08edf0f1cec717defc91d1e72fc905b40315d726f6c522
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:3b101bba33176238ff72548c8d0b61e07eb17d7ff1cc0e96763a06faa50e13ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:cd10e5409787cd3384f9d2120a36d1c70ea129fcc1cd380313d90beadfb80392
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:f20a7a89949e54b2e378829c4b3a22288be2e7866d7673575b180de0b4dba6d6