Sign inSign up
Ceph CSI Operator

dhi.io/ceph-csi-operator

Ceph CSI Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.0-debian-dev, 1.0-debian13-dev, 1.0-dev, 1.0.5-debian-dev, 1.0.5-debian13-dev, 1.0.5-dev

Index digest:

sha256:a0fbe042a6cac47b3b304e8b893e494855e04273440ee1b6674d20db50ac7807

Manifest digest:

sha256:765f6bdf0863f35076e1e7e197c55541e8aff6a3e7e2ca67aefe9e3ea4120d57

Size

51.73 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph-csi-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph-csi-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph-csi-operator@sha256:6dc4dabfaf4dbdc01934486a46f5a1da1feab9cbd06489dc3dcc768023f7e7e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph-csi-operator@sha256:f73fd846d9bcecc613e540a8806c5fe7cc36bb58b10bde1eeb140ebcb1fd7164
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph-csi-operator@sha256:a087f6eae3f47521d31e90d883177d4086d34f36f4ce53bff64ede2203d8b232
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph-csi-operator@sha256:aa6e4ca6e8a452528ed706a79cba0d1d38d12d17dfe26d62b7f9849d8d74c712
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph-csi-operator@sha256:d1c1cd03440525070cfa4b15ff0fb0fcb25a04d3ded951cfa675abde518e80d0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph-csi-operator@sha256:e8ca96f1eeceffe967bcf7b34c6fb04e047ffb5f7dc7c74105b70c93865667f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph-csi-operator@sha256:df20093bc8b5d98df05b1fdf77af9ad46e5e6b150b449fc3a9ae9b56b603a05d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph-csi-operator@sha256:6e2a7483220603b13cdb38ce1c1f1defd6141aa75773722d8c31e046f89efddd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph-csi-operator@sha256:021028b81130d53ef55346727627568698bd6ea938f5d426e57e048f6c45c403
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph-csi-operator@sha256:3d7f16c21c35f4b03ad7cce9d957bc9c2e6a13add15e7e6088aa730e29ca4d4b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph-csi-operator@sha256:08ef624e78fba8d8ad64ee101f2a1650cc75220f75d47dd8acc604a517c5c4c4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph-csi-operator@sha256:96dea3cabab7017ecad867f45c0be32abb5af034cf03152074c39f3738f6e4fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph-csi-operator@sha256:acdd547743ce8d73d901171af6bd092a917da88d3cc01d446c4714fba47d4466
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph-csi-operator@sha256:426c1cf31624dd6975b3468123df8948b390fd62453f384b36f6b03a0b4bf2ea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph-csi-operator@sha256:6345590fad0205eb0ff4ca31358bd392e95c352e5859ede6e9c17a11b7fbba8e