Sign inSign up

readystack/syncthing

By readystack

•Updated 2 days ago

Image
0

1.4K

readystack/syncthing repository overview

⁠Syncthing

Signed: cosign SBOM: SPDX attached Provenance: SLSA v0.2

readystack/syncthing:v2.1.5-CE-ubuntu24.04-r1

A cosign-signed build of github.com/syncthing/syncthing v2.1.5 (MPL-2.0), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

Signature, user, attestations and grade below were measured on the published digest sha256:5e0be82bc9725b9c2e2dc1a4964daf9d884fdbae6ad2b8662de15d11b1eb36f2 on 2026-10-07.

  • Docker Scout grade D (44%) on 2026-10-07 — 4 of Docker's 7 default policies fail:
    • 1 fixable critical/high vulnerability (1 high) in 1 package, e.g. openssl 3.0.13-0ubuntu3.15 (fixed in 3.0.13-0ubuntu3.16).
    • Provenance attestation is SLSA v0.2; Docker Scout now requires v1.
    • Base image docker.io/library/ubuntu:24.04 has been updated since this image was built (built on sha256:023f8a753c22…, the tag now points to sha256:534baea6a22c…).
    • 87 packages carry copyleft licences (GPL, LGPL, MPL), all of them operating-system packages.
    • Measured with Docker Scout CLI 1.26.0 (docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue⁠.
  • ReadyStack release check — passed at release on 2026-09-27: no fixable critical or high vulnerability (Docker Scout and OSV), a non-root user, SBOM and provenance attached. This is ReadyStack's own test, not a Docker grade; vulnerabilities published since then are in today's result at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key (fingerprint 04daa92344a52dbc) on this release's index digest sha256:5e0be82bc9725b9c2e2dc1a4964daf9d884fdbae6ad2b8662de15d11b1eb36f2; verify with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/syncthing:v2.1.5-CE-ubuntu24.04-r1.
  • Attestations — An SPDX SBOM and SLSA v0.2 build provenance are attached to this digest (Docker Scout now requires SLSA v1).
  • Runs as a non-root user (syncthing).
  • Built from source by ReadyStack.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is v2.1.5-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement⁠.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/syncthing:v2.1.5-CE-ubuntu24.04-r1

# ✗ unsupported (do not pull)
docker pull readystack/syncthing:internal-...

This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/syncthing:v2.1.5-CE-ubuntu24.04-r1 (the signature is recorded in the public Sigstore transparency log). Support: [email protected]⁠, as set out in the ReadyStack Agreement⁠.

⁠Deployment

Single container running syncthing (pure-Go, CGO-free) as the non-root syncthing user (uid 999); syncthing's own monitor process is PID 1 and runs the syncthing worker. Continuous peer-to-peer file synchronization. State lives under STHOMEDIR (/var/syncthing/config): config.xml, the device identity (cert.pem/key.pem), the GUI HTTPS certificate, and the folder indexes in an embedded pure-Go SQLite database under index-v2/ (main.db plus one folder.*.db per folder). No external database server, no docker-compose, no Kubernetes. The image is the complete running instance.

docker run -d --name syncthing -p 8384:8384 -p 22000:22000/tcp -p 22000:22000/udp -p 21027:21027/udp -v st-config:/var/syncthing/config readystack/syncthing:v2.1.5-CE-ubuntu24.04-r1

On first start the web GUI on port 8384 asks for user admin and a generated password: read it with docker exec syncthing cat /var/syncthing/config/initial_gui_password, or set SYNCTHING_GUI_USER / SYNCTHING_GUI_PASSWORD before the first start. Scripts use the API key from config.xml (the element under ).

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html⁠. A clean-room rebuild from this release's archive on an egress-blocked host reproduced its linux/amd64 digest sha256:db0686588536a78f685cd313710a5b82d009b4a542f989217ff0c1eb6cf66d92 on 2026-10-07.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:b646eb191…

Size

346 Bytes

Last updated

2 days ago

docker pull readystack/syncthing:sha256-db0686588536a78f685cd313710a5b82d009b4a542f989217ff0c1eb6cf66d92.sig