Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 19.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips-dev, 19-debian13-fips-dev, 19-fips-dev, 19.2-debian-fips-dev, 19.2-debian13-fips-dev, 19.2-fips-dev, 19.2.5-debian-fips-dev, 19.2.5-debian13-fips-dev, 19.2.5-fips-dev

Index digest:

sha256:a8610a2864399e350056af979296513756553c9c7bcd5d66ad72ec402c451904

Manifest digest:

sha256:2c1b9a67e77a4fd942ecb44b152f37856f4f3bf15940066b7680d5e8067edc96

Size

306.78 MB

Last pushed

18 hours ago

Vulnerabilities

2
37
19
35
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:19-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:84808166fa6602a477d832d9d6be7f4ee9ffb63baf1862d239bdf384afce9806
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:573612cd7a504b163ea39e1e48fee234fff64f9e354eb393e97ce9f65683630c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:28d463045f7421d8df8c3b3acbc4c450bebea1b4d20217016a2bef3c1afbbb9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:551c9c1cbe7ab65fd53c04f10b5ebaf4873724928bff05209f41758a2c91e82f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:45147c87806298ab62e185874e97a7d41289a869b5a70d4db58bd327d4e27988
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:2259f68167bbfe519fce68c830fc7bf1427cabb0762e03ff414cfdb9bf82c7a7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:1822f77c1386a70cdce25bb21c12d6878d6c94583a8a002bdb0a80fd4e86a88d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:42dd1cf3b71ab5227a4fb2e29e35d199a8ddbab2988623502118e43bd645471c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:213aaabc763ff569f172814e24c868acdf7b21d3ed0ddc59dc2e74dd25a6aabc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:082e031157ad1b5100d21201511cce9bb8d1005e256ed507f4a64112857c8339
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:f5218a38e5ea27a94c2c74901314fa6b3773e09bea611fb7906c985b3f7a7bcc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:d57a05430371f7162be1998503c9e365fd811adb803100745b2922ccf7798dab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:5a3c953366baceeda395b8bfecc11f62f0496a1a9367debfd09986db99508d8b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:7bb2f1cd1945b52de681734745ad1c5f70e8fa5b0cdad65245256db67bbbece5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:7bbb4f83bfb1f855ba99e4ee139903e187785e73d41dae791fad31907da806fe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:b0d4324178e52c39411096305d1f64160a3fa5838b3a56ce410f8488d2fdbbd9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:9fc4a6ba98ce6003dfe9ac25cc4f787ccc840cccc5f53fe70183f016b7f7657d