Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips-dev, 21-debian13-fips-dev, 21-fips-dev, 21.3-debian-fips-dev, 21.3-debian13-fips-dev, 21.3-fips-dev, 21.3.0-debian-fips-dev, 21.3.0-debian13-fips-dev, 21.3.0-fips-dev

Index digest:

sha256:c7a5c8d340e2f5df951d3b909bc4ff0d9d2b5c78aa9a62f45260a920c7f86b04

Manifest digest:

sha256:5d9509697b44aba3c844e3e771fda5ba419f54544fe77a164b5bfedd8c972e80

Size

250.12 MB

Last pushed

1 month ago

Vulnerabilities

2
15
18
19
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:8aafd06f3fd442a6ba4c23a4ef5ab8ac934abe18fbe22b4c3f0a6e044fd73772
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:5e4fc851b4ec8527ed7b055c35b7c2382c75509982ac5f3995482886718bdfc5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:e4f84c84cc6e9cbd74e2417238aada58624e56f29fb08729be9376094ca5250e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:d3781f47fa3cb38287912d64ad6b8a8c2f9ed68ffa101e0242059d717b3e7aad
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:56bdaf132a77d3252b66826a8c274c182c3e43762cd189ba250874b35cc6c2f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:5b1ae36131cc460171c552ab4f9fda8b5a5b5af382c2712882cf6a8284f88d0d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:99e9d873409e2223acb7ebf0e5fc8d67745baf6256e822e9572f4bedb4fb6df4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:0f3d8e2b529fe2d26ce84ec036648112180181befcfc10fb2f0b8f78f0882f7a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:640ed684660abf9aaa4b666e0ed9fc3ba1447960a3de02ebae65151c2193f11a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:d052d6af2357c68c8e0d15355c4297122e38f8447ea3ab247aeab6117a2e2017
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:1299eeaf02214aa1a45bf5c2550986984d2978a040a2c5f84d31ecef24c815da
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:6199a6c43bea70fb495f5f23e8b324c7c64236c291d3e03ba49d4431740f0cc3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:975a3225fdd10d61dd54abb757f84bfb87888c710ecd7826c80887786d97d120
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:c8e13f0f854d6511f9a93f9d6a8a10d73b55a0bf716794784182d3d080be981d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:0e5fdfb12d5f677da962ed266a33f82317318d7d60da53bb1f49c5ac0c81b8d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:0619c8182b360b6b9dc70cba7f454fffe6385ace1e6510d23acd99fad0876eb0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:45f994b5e4918dde65db6d5176a5a412a4bc3f49f6ac55cc37cc768a9afb1e8b