dhi.io/ceph
20-debian-fips-dev, 20-debian13-fips-dev, 20-fips-dev, 20.3-debian-fips-dev, 20.3-debian13-fips-dev, 20.3-fips-dev, 20.3.0-debian-fips-dev, 20.3.0-debian13-fips-dev, 20.3.0-fips-dev
sha256:1a20da8588bbb7a3c2439f24c2125ad127ee491ddfd8226a9712ada0a5c663b5
Manifest digest:sha256:838ff3724b6fc5c6c8ca8e16565563d09101218bb30a8c2c43d4d5602bb51ca1
Size
316.10 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ceph:20-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ceph:20-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ceph@sha256:f43a457c9527221cfb978282e1ff290f36a8848048d435d88a7fbaf1496429ae |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ceph@sha256:a6d7fd12f210623232720035ae7408cb270064589b8ec3944601868b67d63e5c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ceph@sha256:603fc6e361a095a94448b42cd6dae023c0316feb307e7006d29ce3c58b6dd224 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ceph@sha256:586f7ff354f216ab8cd3211f93aa0fe418d450032de9850411ae07983f34e2c6 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ceph@sha256:ff0283cbf0c4f3ce6f707ff55bc5626e7f5258d8961eb8ed09bde4934d82ef91 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ceph@sha256:ab71391060650ecf5ad9bec6f5fe24e296f1d2e9ba5e32a2416f4555ae1d2931 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ceph@sha256:74c50d304d1e3a101f5197e0698f3dae287852044ddee70f82b8c7762776f8ef |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ceph@sha256:49d710f5659b609205cd14e5173dbe55ce707c86a23dfd10eaa9852651fb90a9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ceph@sha256:f778af237901bc8787ab8e1e36bb8eeb523619451e0304d32e0de89024dfb8b4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ceph@sha256:9c9d3cac329a85bbf2d2f56c59c71d6c81d859c874fbefb288492b36430616eb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ceph@sha256:60f224b078b40c31308fce16c726683771614d57160e68803bc8da8a76d6d18b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ceph@sha256:6164a5cde3a6ad34ab2ca42b88edfd80840a0a41892bf2c0b219e3415cbe5af4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ceph@sha256:89c8e11df03c5277fc0d99878ffd00af96b7586f648ca928467dc5b4e00ef52c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ceph@sha256:b6028d2f47e2935a03c3a85d577ec773ad27a0bbe424b996a8f4f213e28c4425 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ceph@sha256:70a6f0e95b621f73dedf8daa5a5a0f88aa5b1fa9dc2f720bae45d2f358909d8c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ceph@sha256:471d5d2a205823a584b87f274ef3e2f94a072be69cd0255665d254a64b432338 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ceph@sha256:a937c0a4d07cb206adaabee975e15a23af4d857fa21e71a88d730cffdb4a2b33 |