Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.18.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.18, 3.18-debian, 3.18-debian13, 3.18.0, 3.18.0-debian, 3.18.0-debian13

Index digest:

sha256:b32d2aef9b2ed06c998dd13367b9720848c4cde1efd6adbc38499b488d91f04d

Manifest digest:

sha256:63bf7612cab1508178b83160a45f6eece0cf19ad911f87b35cb031c40e868d7a

Size

123.89 MB

Last pushed

6 hours ago

Vulnerabilities

0
3
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:e69e2c23b71821f7d6b1e8f7b40d67d1ec92b581ba3d13125b92aea47b23ffdd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:76f28cb2712b8a1a7c2df40faa431a258159a884cfba1a87e07a7a7a80deaa9d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:28dd5b75d0f5d1cadfe1fe5d40494b67a8590041f4db10cc273ddc6d9b212304
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:a8d775cbd0f5d7a6301c85ef8ed98066075e94c2e17e8b5ad447b37564603679
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:60cdc8a514207286499897e4fb9a29885e400d491791c835c6e0cb6cd5428d63
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:03210bb09293bfcf02335e37633adb0b3e8925bad20d26a7f5bc7a32b65f760c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:528729b1565de0e71ff7fe71f5f5409d45275b675078d3a3f7bacfc6366938a5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:3b54f378d868c27755522cf85a38fb8d6326e1fbc9befbfc917cbb614a7bc289
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:a54a00563964669a4c7777d7bc4ee5c9467d7d5fe5b474fb94096ac25d1d0206
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:274f8a047296fb006c38a455479752c074cb79ca0058c5036029fd083bfc2ec4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:7e71c247f368866f056c4d5c6f91a9f315241591b56f1ae0b5293d76ee06fb22
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:6c4cc39e869a10d3de91f48d24c6b6e2c6f4bd41faa6596e79727b1927928984
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:9524ac07f396151a068d53a76e1c35a1e24e44d3dfc68a8c7afe411ae9f7c877
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:69d41cfc6cd125967beda34deace7b160ecdd2f3a544308a5ae04727f2430632
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:038cbb8339541519bab41e1af7bb33abdca6b50b91ba3cca2b116162d458abd0