Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips, 21-debian13-fips, 21-fips, 21.3-debian-fips, 21.3-debian13-fips, 21.3-fips, 21.3.0-debian-fips, 21.3.0-debian13-fips, 21.3.0-fips

Index digest:

sha256:12ca1bddef5628ad0bedf4c7e7315696c02b5c56144b9579f0c180d1d796fe66

Manifest digest:

sha256:c115d12c856f44b1dcea15def76a1818a5d8c02059908a802b07d77b80a5a006

Size

320.55 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
2
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:7d70a59690f9645012b0d27502fe74572fc8802197d6efd129fdb1e4948859cb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:f361d2bdcbfb1d0e4b4e46fae67e4840ce4951539ba066762edf6fad792edbba
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:6f7cd6df830cc392991c28f6cca36b31cd1a97c61f84287bddbb29dc670651c1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:7f33cbee9eb7ebf03b74f199b07b7845f5d0d3fbfa01cf037cce47b026034306
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:e77fddd317ee6790005229c5e5d16952ca2717d7ba8e8b5181f59f7a355adcd2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:32438a117dc305d943769609207abadd3fc32c802ea93d5a6032049596ad1e7b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:781939192675b24a2a1a5f5e60051ff92c438fa3fd43124f1476ed008b0e19d9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:87ba04655af188975f0f9061afa5b673b52aa8c03e7310a40a7e7c9683d24282
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:bfff5507259d988ac52165d3f401767f891f373ef765dada9baab4c822f890a1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:c74585229a9d7e1a2f285f4d88cd07857822f29f4476e02bc5f10ffa3b0005d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:d3c385462878f92479b7cabfaf82ad828db09eb6c3123eb6d84c10ec90531069
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:e3655997fd4af30543be33f1797978e146a16a7c64684b70999dcd80e9692045
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:972983ce9fc91bfe3c962ae28fc5fec0759c91347ea5f65f08fbece54549965d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:6376a70f0d0e2805699d15e5d219976952dc5eb077beb0fc83122fe8a661aa8e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:a16255bd30382b3417656d3852361a18459fec2c92551f14df8513be04f041d5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:fd26946ed2f335fc4362ae3070a7469c1874b0aa86a71a827a139f01ba78e456
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:a3e9d320d2fb22ec1cbafd7669d2502ac58019daa381c7e40d3838527b6b5f9a