Sign inSign up
Rook Ceph

dhi.io/rook-ceph

Rook Ceph 1.18.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.11-debian-dev, 1.18.11-debian13-dev, 1.18.11-dev

Index digest:

sha256:1159e6137896ca788c8a5e1d477e759457c9be57d993c9939d49645b826919e9

Manifest digest:

sha256:9e7ec7ad73ab0645de83ad73becdf8277c240f6ebc1daafd4f2fff4d72bbdfff

Size

356.30 MB

Last pushed

12 hours ago

Vulnerabilities

1
11
5
7
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rook-ceph:1.18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rook-ceph:1.18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rook-ceph@sha256:51cc1bbe058823c80cd0643bf88ff703e7a4edd3f738b13eb8763d923be57059
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rook-ceph@sha256:7c44f16dd27e988a4328f6c790547e972b64b6fce51be53eb41df7a4885b6edd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rook-ceph@sha256:ef02300618787d823d5f189c5565323c79faac0d3647440f7fb8be0130033a01
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rook-ceph@sha256:376009b219cbc300be94447d9fc2cb23acd265f442b284827399f5673ae172bf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rook-ceph@sha256:2c25666f3721d6d85f8a34a5797a0348d6ab042225702e44c07f21717781e0fb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rook-ceph@sha256:7d19458e1b4094337a7bcd7679d702424ba38eee2a3d2591b3a3d840853dd962
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rook-ceph@sha256:74d2c11822e8a92cbb8d733310b6d82d9ac866be7e82c0736398a43911d4d6d7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rook-ceph@sha256:be8d4b421189ef6e0ac45ca11cf5d26fd30528c2de866698a223566428025274
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rook-ceph@sha256:26e63b6872a3734b90f07d51597d92be70f93397422d885e9615eae38e69ea08
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rook-ceph@sha256:5dbf397610778fd12913c9736bf0d8b99cb1c2118d7368d0b28db936664cf2db
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rook-ceph@sha256:5da49e98a6d0bce4f51bb037f09a7819bccb90960d4bdd2d743807bf05d6fc0e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rook-ceph@sha256:b649d0b7b558a40246f0985dedb51c451f03ba58ae18cbac432a1a6b206b7a97
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rook-ceph@sha256:c6e745d230e1b786bfdc42c31c9748bfc97e11375eb4ef8433ff6f235b9db5ca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rook-ceph@sha256:699b4a57a818630e7c346a21fb787348aeb3c9788c98ae5ac53497b994434046
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rook-ceph@sha256:1850fab55a7c15e52d940015fef07c3b431725eba6030bafea31be8872ea0041