Sign inSign up

readystack/bookstack

By readystack

•Updated about 11 hours ago

Image
0

1.9K

readystack/bookstack repository overview

⁠BookStack

Signed: cosign SBOM: SPDX attached Provenance: SLSA v0.2

readystack/bookstack:v26.05.2-CE-debian-bookworm-r2

A cosign-signed build of github.com/BookStackApp/BookStack v26.05.2 (MIT), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

Signature, user, attestations and grade below were measured on the published digest sha256:3ad77a5e31c3a74644f8094caf0287e2105c785d0c704eb66d178dc3d6f18791 on 2026-10-07.

  • Docker Scout grade D (44%) on 2026-10-07 — 4 of Docker's 7 default policies fail:
    • 21 fixable critical/high vulnerabilities (5 critical, 16 high) in 6 packages, e.g. perl 5.36.0-7+deb12u3 (fixed in 5.36.0-7+deb12u4); openssl 3.0.20-1deb12u2 (fixed in 3.0.22-1deb12u1).
    • Provenance attestation is SLSA v0.2; Docker Scout now requires v1.
    • Base image docker.io/library/php:8.4-apache-bookworm has been updated since this image was built (built on sha256:7d9373f20aa7…, the tag now points to sha256:9e811795a606…); Docker Scout's own lookup passed it, which happens when Docker Hub rate-limits the lookup.
    • 118 packages carry copyleft licences (GPL, LGPL, MPL), 112 of them operating-system packages.
    • Measured with Docker Scout CLI 1.26.0 (docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue⁠.
  • ReadyStack release check — passed at release on 2026-08-20: no fixable critical or high vulnerability (Docker Scout and OSV), a non-root user, SBOM and provenance attached. This is ReadyStack's own test, not a Docker grade; vulnerabilities published since then are in today's result at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key (fingerprint 04daa92344a52dbc) on this release's index digest sha256:3ad77a5e31c3a74644f8094caf0287e2105c785d0c704eb66d178dc3d6f18791; verify with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/bookstack:v26.05.2-CE-debian-bookworm-r2.
  • Attestations — An SPDX SBOM and SLSA v0.2 build provenance are attached to this digest (Docker Scout now requires SLSA v1).
  • Runs as a non-root user (bookstack).
  • Built from source by ReadyStack.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is v26.05.2-CE-debian-bookworm-r2 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement⁠.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/bookstack:v26.05.2-CE-debian-bookworm-r2

# ✗ unsupported (do not pull)
docker pull readystack/bookstack:internal-...

This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/bookstack:v26.05.2-CE-debian-bookworm-r2 (the signature is recorded in the public Sigstore transparency log). Support: [email protected]⁠, as set out in the ReadyStack Agreement⁠.

⁠Deployment

Single container (Apache + mod_php, one foreground process) running the BookStack Laravel/PHP application. It REQUIRES an EXTERNAL MySQL 8.0+ / MariaDB 10.6+ database the operator provisions and points the container at via DB_HOST/DB_PORT/DB_DATABASE/DB_USERNAME/DB_PASSWORD env vars — there is NO embedded/SQLite database. BookStack creates and migrates its own schema (php artisan migrate) on first start. NOT a multi-service cluster and NOT docker-compose/Kubernetes-only, but it is NOT self-contained: a MySQL/MariaDB server is a hard external dependency.

docker run -d --name bookstack -p 8080:8080 -e APP_KEY=base64:YOUR_32_BYTE_KEY -e APP_URL=https://books.example.com -e DB_CONNECTION=mysql -e DB_HOST=YOUR_DB_HOST -e DB_PORT=3306 -e DB_DATABASE=bookstack -e DB_USERNAME=bookstack -e DB_PASSWORD=YOUR_DB_PW -v bookstack-storage:/app/storage -v bookstack-uploads:/app/public/uploads readystack/bookstack:v26.05.2-CE-debian-bookworm-r2

Generate APP_KEY once with: docker run --rm --entrypoint php readystack/bookstack:v26.05.2-CE-debian-bookworm-r2 /app/artisan key:generate --show (a literal placeholder key makes every page answer 500).

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html⁠. The latest clean-room rebuild from this release's archive (2026-10-07) did not reproduce the published digest (first failing step: digest_match).

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:e850d6168…

Size

352 Bytes

Last updated

about 11 hours ago

docker pull readystack/bookstack:sha256-b8880fb4b868618176e2e7d204b614d9f699c63625d60b763f00e686700ba6f8.sig