Rook Ceph

dhi.io/rook-ceph

Rook Ceph 1.20.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.20, 1.20-debian, 1.20-debian13, 1.20.3, 1.20.3-debian, 1.20.3-debian13

Index digest:

sha256:a90572fc5bb7aed0f8fb8dc3bcba463f90ed23efa81f39d732e34a3dd209eea1

Manifest digest:

sha256:f53ad899fa4f9af1c1508e7c419d86fc83f90eb72119918d9f5931f41aeb21cb

Size

260.26 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rook-ceph:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rook-ceph:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rook-ceph@sha256:31c2a202b8141b3fb4708ccdcfe2a2280e91d1918f154a55a67e4785505d3b0b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rook-ceph@sha256:53696a3922f4f00bf8e50d01a65ed1b362e223f8d03c8cb86c9c3e9163c4f343
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rook-ceph@sha256:1fdbb2ac59f50e5e5d7f5f8433b019346ac6a34c870f26bb1bc97d95d2ff78b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rook-ceph@sha256:51e20e2afadbcf04c216994766e692a22ac59a40514f9d441f553ba3cfb1d4a4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rook-ceph@sha256:7db49aba672951d73e4e4ddc935ecf8cc12b4a7a8a6551193f5289433eb745ca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rook-ceph@sha256:2dc5c8caaccc0a70b923f0db2879891c9693b52287cbf14d88c839f1fd250477
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rook-ceph@sha256:e46f83e8cb5b4712be75869ec07d95906e520ffba18ad5518a37b745d957cafc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rook-ceph@sha256:f874344cea2660f9674177bd7c06a4a31108c8f85ed04729b13b73a7a2c3651e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rook-ceph@sha256:cf90ec89a1f78284b6c6162212343e11e466adaa03de3d16bfa7434b0cc6ea23
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rook-ceph@sha256:fb5585dfc14d228315d69d67dc37ddb7d974591bcabf7bd97692342a809e3879
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rook-ceph@sha256:15ea61cf1800d6e3f0049166e9b7ee5fce19bacf93dab1fd91cee58038700399
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rook-ceph@sha256:25acc53d2b9c36148aa53469f2a66f0ab46fa516c59740720b0c6f42e3596a6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rook-ceph@sha256:7936bf975ea105d91e5e009323c85660b3aa1c0a9f93b1473ecef4d167680299
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rook-ceph@sha256:66ea676ae615433cac95573f7b0bfef531d4085b3f5de02dd28875c3b7c2b3a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rook-ceph@sha256:cdad279dd560de9ebe76afc2d60cb006d4cd588c69902d712c5da1e91607e945