Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.17.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.17, 3.17-debian, 3.17-debian13, 3.17.1, 3.17.1-debian, 3.17.1-debian13

Index digest:

sha256:d54348f9321ce5f1fbc1bc52439e53fd3455d4e268fda66e9a8f350708cca394

Manifest digest:

sha256:cad8a2de4dc399446f01e421ad7e025b840a41d29b5323e738a24fff5d7c6756

Size

123.75 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:1d727cb2f9410882c0df251cf152d67745ef254c0453e280c36abcb795bc18ec
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:caaca4c93674aac24abadb33b4f8cf414378ec8bde1e88b26834db8b8dc8f2d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:7f4f9ad83762d2bac8449abc320ca90958649c3cf277076350c235a87099d6d7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:a8de9f769fad3219be48b1b3c6b88f60f95b84cfd9a10730f58b99e21d9c429f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:98e8acfaaf5a610f317aad1eab7235e8dea788ab4da61377b2f9655c3bad5d4e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:ca38ae570ec5c19ddc6cf31bcba58617c1bf64eb9386bf45a9ca20231404b323
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:7d5adafba0c176969ee5f69e1d55c58dd506b934e1e78f73d2c860dffc1e9f04
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:8c925b59801746c3c801370ae2154264223964e04daa460f0b04444ea371182c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:930087fdf2d0b7f6fb771e8b787d515c08b2c1c1c27face75449a0166908b9e3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:37ce580bfd258df2330646aa3720fa8fc766be70e68dfce6e3f89c385309802d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:1cb6d90ea0ada72b5abc7fa5326ef26a0eb5d83bf7c49ae61947cb18135f9e9e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:695dda2448d0f6a073a2cf2c1331b9829bd8dabac91c9b4c4083b39f5ed5c34e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:7d96630c7750828e568506b37b2eb91adb01fe890a7c75d75d763695f44e80c1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:28c399b344fe7dbb8a13a44e477cce34e6b1a065906da595a877ae7be74afd24
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:2cbdaa659bb3f3156d6b6d8a58ab73dbea7ad25cec2bf9072aec328b162fb5dd