Sign inSign up
Ceph CSI Operator

dhi.io/ceph-csi-operator

Ceph CSI Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.0-debian-dev, 1.0-debian13-dev, 1.0-dev, 1.0.5-debian-dev, 1.0.5-debian13-dev, 1.0.5-dev

Index digest:

sha256:3e3c189d747ce3f4b87c4da62c5b25ab230d91d5bac13b8b3f1adb0c47f2f019

Manifest digest:

sha256:4d118a293fda1e52280166b9cb1ca2c7625ab082e7b2f27750b43ff072914b67

Size

51.73 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph-csi-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph-csi-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph-csi-operator@sha256:777f07e4c1145cad8427fee1ff03dcea3e23347b79753576e59dd764d4734dcd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph-csi-operator@sha256:9a43181978fea1b8afec3741142a1222f7f87e2f242f665df255238eb1de1751
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph-csi-operator@sha256:d00d6fb22e3284c421d6a8fc267a238bfd478ec6468d88080ad9d55495cd5295
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph-csi-operator@sha256:1eb9e3674395e944ee4e44985d6b360c65761a6c9785cc636483e5a4ffc272db
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph-csi-operator@sha256:992e5ab72977d47e7f1f9e21aeb85bafa0a9e5f8dbd590b80c3918aee892faa6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph-csi-operator@sha256:b6b1103072a1beb17c318a051e2b98fd0384846a01b2c40b6c5b4ef9c102ab0c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph-csi-operator@sha256:7e81c1e90a03369a831a8d89ac4cd48b2455871b517f68e9b096026294e3235e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph-csi-operator@sha256:3d8918f8cf84bfd751680e622900e59519c30d599111e58e86be552c380c9800
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph-csi-operator@sha256:9df464cc9b1ab4647e1f1553957ba4fe3bd2e82481b0abbdbbd5701b8e5063f2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph-csi-operator@sha256:29f652a178dbf54f762bf23414096e0bb85fec1773ea4fe4c368ae7329d5a333
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph-csi-operator@sha256:ff30899824f6361578169ea08d950a92a948bbd48bd3b440c68d099f8e013ad7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph-csi-operator@sha256:e166ac5a143bc08d96dd2ccd42f98535c252b6369fbd346d310e03eef4e368ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph-csi-operator@sha256:9a0395da4be8ce4a88210310162f2205cbf3b2a62bb16bed6fad09e2f276c0b9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph-csi-operator@sha256:d969e1382c38028be67fbd28d5a8120239d54fb035d2f37655a19a5a1a4d2602
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph-csi-operator@sha256:87236456611b4d32fd72e89379b2168d2c8bce2dfc1563104db91ee50aa59b8d