Sign inSign up
Rook Ceph

dhi.io/rook-ceph

Rook Ceph 1.20.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.20-debian-fips-dev, 1.20-debian13-fips-dev, 1.20-fips-dev, 1.20.7-debian-fips-dev, 1.20.7-debian13-fips-dev, 1.20.7-fips-dev

Index digest:

sha256:f4699a345153b180d8bc38c50123007bed66ea7b511eadbc5adfcab0a1cde8b4

Manifest digest:

sha256:c974ddebefa4631d68d1260ecc2d0c45c7af26a749333263e3db6eac2b43015a

Size

301.03 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rook-ceph:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rook-ceph:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rook-ceph@sha256:593892c5b38b78cf50635cfd9d8bf04d99746a692707e05fc2a57491f89c5f88
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rook-ceph@sha256:4aa0f4c7c971a7d0a623d3723fb2bc728722344d78e3f6a177336485df4b2025
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rook-ceph@sha256:50dbf8c746550aff7500b42ef570174c504abba7ceb2363defa90d111479b7ca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rook-ceph@sha256:24a6e9df6f9f921956334d80f823d3afc1af62a2b1c6e58506ae95c1b7c14802
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rook-ceph@sha256:cb4b7aed629a0198790344c49fec8a6982584582a09538cb4ffb7ebef1c26c13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rook-ceph@sha256:f2a2ba42f0f2e7de01fe85cba3e7165586a15802623b53b272a91dea1205d303
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rook-ceph@sha256:4f974f75a86b091d91c48b7b7ae875b4a61c950a27b6808307be07c73731092d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rook-ceph@sha256:20eea0a743ca5f564036994baccc4448e6fe8e722b25f230bd8d8802ecef169e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rook-ceph@sha256:671a6ad256d1e86f8ba47afd4b6c6791dc2d8643e6389f0dd8bda03f23c7c8ee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rook-ceph@sha256:535bc88f5f57896a0c7178fb7c8dfd057a4ccf1c304269f90e596aaa76a56c92
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rook-ceph@sha256:23a0a76606d10fd4a4fdb53c78b916115002ccacd8e93906b3cae787f250ffd3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rook-ceph@sha256:81e3df55401c2b4a846bd6916da0f59313218d0c3c8b3cde5f43de5ce2b8832e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rook-ceph@sha256:a785b7ef863d0584537802656cd1c8384316bb34720cbc2e542735d731c3caa5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rook-ceph@sha256:37782690ae2fb37a23ce6a10eac4461cbf80c4a7a2fdf7685d177d4a8a4e5087
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rook-ceph@sha256:cee02a0ba864de37c16989d64ac386baa3a2a0af4606e4add3866afa888f4167
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rook-ceph@sha256:564ea766a23a8a09a9964877d856047c9ecad55482ee92d24c4e57e8d03a996e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rook-ceph@sha256:a16be537dcd39b3025ce4a8dde6663ea4c581843840942fda24fc078918ec933