Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

19-debian-fips, 19-debian13-fips, 19-fips, 19.2-debian-fips, 19.2-debian13-fips, 19.2-fips, 19.2.5-debian-fips, 19.2.5-debian13-fips, 19.2.5-fips

Index digest:

sha256:60e98958e3c89e8d52de586c5bc1202baf73ed07fa8acb0385159a2301430d0d

Manifest digest:

sha256:8eb164eb741e4d72eba2fc5a65a9ccb38a99343c7059eee9baec380d6a36ae8d

Size

301.79 MB

Last pushed

13 hours ago

Vulnerabilities

4
40
15
32
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:19-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:78a05bd4089435df5bf788a5529f1b2a017f41059776651ba438da7e2c985a2b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:e3537ed25a79953b2a83027b5e2236b39c473d615db024c7ee1aa20159928896
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:9d48ab4ee90399001a48d86a7598dfbda672aaa2e76da12c283fcdeda8a1ff9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:902a9e2ed8965a75618b97ddf6b7d405c556158a37117a240e7cb163d7203988
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:2dd79baffb539c0da515c9d4b336c31d975ceced360b061f848b03a04f4b9be9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:0078dec2c13eb204c476b0ab6c0e0f4b036471f03739950ae43e0f5ac1b71f90
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:674c5861bd849e36480d4e53ff6526058e46d5131a64d70c4d0fa190ff8e7251
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:34c18fba5656bb38bd556dcc280c0f667627b80dcb56db45c05ff6db84acb6fb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:4d6657675565583e19b2fcadd3bd5f385728f9a1f622a3f4a88c37eb9fea4cfa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:88d2dab60a6e974bca7a58ed374d9b2e631e69838215579bfc179b66000d2ec0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:0f0b5018a9e58d937d0fb6582187d34f085ba6387fed76ecdbbdf3a8969d0b58
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:5aeba332f6849c1860bf8eb460d6d404b36081948bba1bcd99e6c37f7f584ea4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:8a5870a4111384156a97fea9d7101ac18cdeaee587f6a561cca3ee714928845c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:771ebe0c956d23e3530424e077c2de7e43977596bacbdd5db2aba74e6e25cf4f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:75d3195ccceaf5459fe9846283ab66258ee8b7f97852dbbaf5ae7175a8f9ac7c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:d419d238a7c88229c7b01f009bfaa9bb94f07f172efa4f4508670a9338352f79
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:b5d8717c4c5d380d11718e694c136a6aba20c6d93d333a63a11ffaed46734fbf