Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 20.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

20-debian-fips-dev, 20-debian13-fips-dev, 20-fips-dev, 20.3-debian-fips-dev, 20.3-debian13-fips-dev, 20.3-fips-dev, 20.3.0-debian-fips-dev, 20.3.0-debian13-fips-dev, 20.3.0-fips-dev

Index digest:

sha256:1a20da8588bbb7a3c2439f24c2125ad127ee491ddfd8226a9712ada0a5c663b5

Manifest digest:

sha256:838ff3724b6fc5c6c8ca8e16565563d09101218bb30a8c2c43d4d5602bb51ca1

Size

316.10 MB

Last pushed

2 hours ago

Vulnerabilities

2
31
12
28
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:20-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:20-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:f43a457c9527221cfb978282e1ff290f36a8848048d435d88a7fbaf1496429ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:a6d7fd12f210623232720035ae7408cb270064589b8ec3944601868b67d63e5c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:603fc6e361a095a94448b42cd6dae023c0316feb307e7006d29ce3c58b6dd224
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:586f7ff354f216ab8cd3211f93aa0fe418d450032de9850411ae07983f34e2c6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:ff0283cbf0c4f3ce6f707ff55bc5626e7f5258d8961eb8ed09bde4934d82ef91
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:ab71391060650ecf5ad9bec6f5fe24e296f1d2e9ba5e32a2416f4555ae1d2931
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:74c50d304d1e3a101f5197e0698f3dae287852044ddee70f82b8c7762776f8ef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:49d710f5659b609205cd14e5173dbe55ce707c86a23dfd10eaa9852651fb90a9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:f778af237901bc8787ab8e1e36bb8eeb523619451e0304d32e0de89024dfb8b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:9c9d3cac329a85bbf2d2f56c59c71d6c81d859c874fbefb288492b36430616eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:60f224b078b40c31308fce16c726683771614d57160e68803bc8da8a76d6d18b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:6164a5cde3a6ad34ab2ca42b88edfd80840a0a41892bf2c0b219e3415cbe5af4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:89c8e11df03c5277fc0d99878ffd00af96b7586f648ca928467dc5b4e00ef52c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:b6028d2f47e2935a03c3a85d577ec773ad27a0bbe424b996a8f4f213e28c4425
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:70a6f0e95b621f73dedf8daa5a5a0f88aa5b1fa9dc2f720bae45d2f358909d8c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:471d5d2a205823a584b87f274ef3e2f94a072be69cd0255665d254a64b432338
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:a937c0a4d07cb206adaabee975e15a23af4d857fa21e71a88d730cffdb4a2b33