Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 19.x

CIS
linux/amd64
debian 13
Tags:

19, 19-debian, 19-debian13, 19.3, 19.3-debian, 19.3-debian13, 19.3.0, 19.3.0-debian, 19.3.0-debian13

Index digest:

sha256:b762479d23ef59e33cd9c951d4770c26a0716d8b0dfc68d61d14a6c959d11cb4

Manifest digest:

sha256:693bef3bc5ac49791dec022a86b1b7e743d4960a34d14ddcdcd2d32e0623628a

Size

219.58 MB

Last pushed

1 month ago

Vulnerabilities

2
16
19
18
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:19

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:19 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:b638de47d37267162c38c13eaa68f8d50635540fcc131122887db99065c3522c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:3f38818fe80cddfdc04624239f7e444158aa6b9833cef1b8c618c095658b3f4d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:a8a3f238e6254582a4a0e201549c0495c60822841fec033cb9b8efcba9f5631a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:1f46c11fde933b31bca530d8a518e8d702acc30cabb90e82408051bca560c6f0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:c440077d9974d9bacd4399b57a434c15dcf71b54331719af09b2d8b8a7b5be2e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:3340f90facef240cd6e7b04deb9d673f8ea01897e84cc88615821a61f29c516e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:5831831878f23df97f2196bf0ef8e1dc04fab3a0db56e6e218916edfc3284679
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:bcb2e8bde20a56e939e8f63b51a22ebfd10b6a03889866063f5818fa34bc6dfc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:95aeb5f2ac4b88d7a5ea4e2b1302f0694c08318701aba0883e0e392848fec794
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:23d6f417c33bc6f21f9760975627611586c07cc0e25c6ba4fea11dc01c3e0cfb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:f22864ebf0855c28c399adb7f6db0bfea5382fa18f6c3ca138068f0c05d0fac3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:f9dae0fd7826380fc1e7f9ce99bcffcdaa6fd72c9a54cef353f1ec9f41fffb14
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:b68c5f0d6c33e000ef8fccc1c14e6f4a910ba647f27a2e93f9c200ae1747aa3a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:4c7e2f540bbec4a3d89e8ce64fc09c3f96e3b8c56929a8f618c68f4cbbe211f4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:0d85d0f0bd957869e8c80e5e7c46b337319e699c51307c274a1de26597c8cbef