Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.17.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.17-debian-fips-dev, 3.17-debian13-fips-dev, 3.17-fips-dev, 3.17.1-debian-fips-dev, 3.17.1-debian13-fips-dev, 3.17.1-fips-dev

Index digest:

sha256:26eee47ebaac0b5412e5791fa35ee214e426b5f0b6e5418f020cf6d14e4222f8

Manifest digest:

sha256:78f49b86be56ee942b50e490b01a42213e442a324bdc7489accb3aa4d2f490fc

Size

145.71 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:7e4cdc7a916d6c8083059e821eec155bf5d20f9d76b5972c2bc523048865f48e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:7591a87b930e0f0c49d1e0d965d77aa9f74d1713f4554b185b173aafbf72a034
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cephcsi@sha256:4297ab1b71f01ad631e40677a7f97dc58779a158520933326db229bdbefc1afe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:611a22831872ff23a0e36a8edd848c3a3fd76fce5b56bbb595615abffab4ce02
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cephcsi@sha256:9d9c8798fd06a43f093fe4470b646f374e0e00dd069ffbe6a1e7744e9ed726f7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:32ada57d0134f70033ea4d0db1b8753e343f80c88af01cb2e5ff2a3b142fcbfb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:1a811c29c918f7784c82ce82e8e738989a312513e5237ddd7af42579b92c8f11
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:f9ee0d205172ac5bcce34ff124634da1d5103faf3aa98d26644feadf6c9ce1c2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:aa3a9d8f3b8f74abaa4fcd05f4ddfa4775689f46dde9fab69e79a01cb4e861b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:b1eb9b9891ec1a70b9584aee235b79cfbc6ffca255d470288741807e6cbf2448
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:483efbe93e86174a7871a94769e0b7843af663a146ad068e093d70d5e80143bd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:f4f514428343e207857bb20aef814a5842d251b32fed6fdd0847684a37e07274
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:4bf75ff7de7872799653876ba5934b6050a62fa9132c9b4223d2d7e4afad0ff0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:82d52ace179623ae15ab8e2b5456a6ea1f754444f96bb39e4a8f2d9a84e9a5fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:8bedad0163ed65d0089a3e4edfc1785619f6bc91ddbce0763c315ebb41a18893
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:0e9f2f9fe00ff6125c459abce44907e2034cc2882e0080cd5dae3bb4e38cf349
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:228a742047c3c8064656d600711c400871a39d50c8667bc71a7f1c475f573fba