Sign inSign up

readystack/canvas

By readystack

•Updated 1 day ago

Production-ready Canvas LMS in one command. All-in-one with PostgreSQL, Redis.

Image
0

2.3K

readystack/canvas repository overview

⁠Canvas

Signed: cosign SBOM: SPDX attached Provenance: SLSA v1

readystack/canvas:v5.14.2-CE-ubuntu24.04-r1

A cosign-signed build of canvas, built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

Signature, user, attestations and grade below were measured on the published digest sha256:9e5a0750250b3b70e5e11b0f6ba7fe94d7a549eeed642dcdc1f59feef6171211 on 2026-10-07.

  • Docker Scout grade D (33%) on 2026-10-07 (or D (33%) if the unconfirmed check fails) — 4 of Docker's 7 default policies fail:
    • 500 fixable critical/high vulnerabilities (60 critical, 440 high) in 108 packages, e.g. linux-libc-dev 6.8.0-101.101 (fixed in 6.8.0-106.106); Go standard library 1.20.10 (fixed in 1.24.13).
    • Carries CVE-2025-31125, CVE-2026-31431, on Docker's high-profile list or CISA's known-exploited list.
    • Docker Scout identified docker.io/readystack/canvas:v5.14.2-CE-ubuntu24.04-r1 (a ReadyStack image) as the base image, so base freshness could not be judged; recorded as unknown.
    • 235 packages carry copyleft licences (AGPL, GPL, LGPL, MPL), 212 of them operating-system packages. AGPL: @instructure/canvas-rce, @instructure/grading-utils, @instructure/i18nliner-canvas, academic_benchmarks, canvas-lms.
    • The image runs as root (no USER is set).
    • Measured with Docker Scout CLI 1.26.0 (docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue⁠.
  • ReadyStack release check — not passed at release; this release is sold below that bar, and why is on https://readystack.dev/queue⁠.
  • Signed after release — this is a legacy release, published before ReadyStack's release gate and never put through it. It was signed later with the ReadyStack release key (fingerprint 04daa92344a52dbc) so you can check these are the bytes ReadyStack published; the signature does not say the release passed the gate. Verify with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/canvas:v5.14.2-CE-ubuntu24.04-r1.
  • Attestations — An SPDX SBOM and SLSA v1 build provenance are attached to this digest.
  • Runs as root — the image sets no USER, so the container starts as root. Run it with --user or behind a non-root runtime if your policy requires that.
  • Built from source by ReadyStack.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is v5.14.2-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed after release (legacy), attested (SBOM + provenance), and is provided under the ReadyStack Agreement⁠.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/canvas:v5.14.2-CE-ubuntu24.04-r1

# ✗ unsupported (do not pull)
docker pull readystack/canvas:internal-...

This legacy release was signed after it was published, so you can check the bytes are ReadyStack's: cosign verify --key https://readystack.dev/keys/cosign.pub readystack/canvas:v5.14.2-CE-ubuntu24.04-r1 (the signature is recorded in the public Sigstore transparency log). It was not put through ReadyStack's release gate. Support: [email protected]⁠, as set out in the ReadyStack Agreement⁠.

⁠Deployment

See the ReadyStack Agent-ready Archive for full docs.

docker run -d readystack/canvas:v5.14.2-CE-ubuntu24.04-r1

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html⁠.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:289f5ef9e…

Size

332 Bytes

Last updated

1 day ago

docker pull readystack/canvas:sha256-362bf360cae847e6f6e49f8eba45a15e880593b09ffcc2031ee364813f573600.sig