Sign inSign up

readystack/ghost

By readystack

•Updated 2 days ago

Image
0

3.1K

readystack/ghost repository overview

⁠Ghost

Signed: cosign SBOM: SPDX attached Provenance: SLSA v0.2

readystack/ghost:v6.65.0-CE-bookworm-r1

A cosign-signed build of github.com/TryGhost/Ghost v6.65.0 (MIT), packaged from the [email protected] npm release tarball, built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

Signature, user, attestations and grade below were measured on the published digest sha256:ff83cb866467156e3bf939b180868b46db7ae67c1ee080844a15a4816a59d606 on 2026-10-07.

  • Docker Scout grade D (44%) on 2026-10-07 — 4 of Docker's 7 default policies fail:
    • 27 fixable critical/high vulnerabilities (5 critical, 22 high) in 11 packages, e.g. perl-base 5.36.0-7+deb12u3 (fixed in 5.36.0-7+deb12u4); axios 1.18.1 (fixed in 1.20.0).
    • Provenance attestation is SLSA v0.2; Docker Scout now requires v1.
    • Base image docker.io/library/node:22-bookworm-slim has been updated since this image was built (built on sha256:8607a9064d4a…, the tag now points to sha256:c3de60bf2f9d…).
    • 79 packages carry copyleft licences (GPL, LGPL, MPL), 76 of them operating-system packages.
    • Measured with Docker Scout CLI 1.26.0 (docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue⁠.
  • ReadyStack release check — passed at release on 2026-09-27: no fixable critical or high vulnerability (Docker Scout and OSV), a non-root user, SBOM and provenance attached. This is ReadyStack's own test, not a Docker grade; vulnerabilities published since then are in today's result at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key (fingerprint 04daa92344a52dbc) on this release's index digest sha256:ff83cb866467156e3bf939b180868b46db7ae67c1ee080844a15a4816a59d606; verify with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/ghost:v6.65.0-CE-bookworm-r1.
  • Attestations — An SPDX SBOM and SLSA v0.2 build provenance are attached to this digest (Docker Scout now requires SLSA v1).
  • Runs as a non-root user (node).
  • Built from source by ReadyStack.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is v6.65.0-CE-bookworm-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement⁠.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/ghost:v6.65.0-CE-bookworm-r1

# ✗ unsupported (do not pull)
docker pull readystack/ghost:internal-...

This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/ghost:v6.65.0-CE-bookworm-r1 (the signature is recorded in the public Sigstore transparency log). Support: [email protected]⁠, as set out in the ReadyStack Agreement⁠.

⁠Deployment

Single container (Node.js, node index.js, one foreground process) running Ghost. It REQUIRES an EXTERNAL MySQL 8 database the operator provisions and points the container at via database__connection__host/port/user/password/database env vars — there is NO embedded/SQLite database in production (SQLite is dev-only and Ghost warns loudly). On first start Ghost auto-runs knex-migrator to create its schema. NOT a multi-service cluster, but NOT self-contained: a MySQL 8 server is a hard external dependency; the content/ dir + DB must persist.

docker run -d --name ghost -p 2368:2368 -e url=https://blog.example.com -e database__client=mysql2 -e database__connection__host=YOUR_DB_HOST -e database__connection__port=3306 -e database__connection__user=ghost -e database__connection__password=YOUR_DB_PW -e database__connection__database=ghost -v ghost-content:/var/lib/ghost/content readystack/ghost:v6.65.0-CE-bookworm-r1

The empty 'ghost' database must exist first; first boot creates the schema, then open /ghost to create the owner account. If the database password contains spaces or shell characters, single-quote the whole argument: -e 'database__connection__password=my new pass $x!'. Ghost emails a sign-in code whenever a staff user signs in from a new browser: if the server has no mail settings, add -e security__staffDeviceVerification=false, or those sign-ins fail (see Sign-in codes for new devices).

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html⁠. A clean-room rebuild from this release's archive on an egress-blocked host reproduced its linux/amd64 digest sha256:40d030778917dbe1433210f4372a229748d2007a8ab0360b0ba96a77ccc3411e on 2026-10-07.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:3d09effe4…

Size

336 Bytes

Last updated

2 days ago

docker pull readystack/ghost:sha256-40d030778917dbe1433210f4372a229748d2007a8ab0360b0ba96a77ccc3411e.sig