Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 20.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

20-debian-fips, 20-debian13-fips, 20-fips, 20.2-debian-fips, 20.2-debian13-fips, 20.2-fips, 20.2.3-debian-fips, 20.2.3-debian13-fips, 20.2.3-fips

Index digest:

sha256:e6beb6f8fd0aacb0e5d41390f8c4c30931c01d29860f339d25927adfd8eca5f6

Manifest digest:

sha256:76e57eac3962261c4171b1cd8bbcf04a2de745547b010c3699b470fd9cdc79b3

Size

313.69 MB

Last pushed

5 hours ago

Vulnerabilities

4
35
10
26
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:20-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:20-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:646369319222b10485df2068b473f9f546ba5c8eeb04358e8625fd404e3cb81b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:cd1c9c7c4df123e2ba0218705277d7754db33c3c5590b4613942c45a4250e7af
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:65e0034107f6b4a2e407d8f66fef34e73c2b2054bb5ed764d55bcf1b516352ab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:8be2bdd9e99605cf65be2e7c7e3936b40af5ba040281696dc2b420f41045626c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:9f660da7beb974e0d8956aa830a660e8dc7b96cec706d6a2832868f8578a8df7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:d3c54a69866d874f9f8c07515d026dbe218fdebaee4ab638cfdc91ff12e4b5f0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:a7489a48a1ffa3bb6734ee41610fbfa1e2ea9f34859d44de8477a587861d9fc8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:3c70d68cd7a832ab668faee427eb4685dd388e2278594f27955576c12bde85a7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:a5b567a33e24e10d5dea1706b7cb2e6eea82d82bfe7cdcaca78dbf3029db208e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:984e19ceb138c3b985fbb818cd79204a67ea1499a90500ceab9f265a6649d2a5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:cf34cab3dce9df84628106f57af2f9db1cf2d44ad0ed757482fe7c8496f5c56d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:7a79d7908152cc22d61e39d65b7a1a5dea0e38dbe068dcf4d498ce8aefb89cdb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:8d431fdf6502e04d29170b517a129046fe13d2b591ed91b3890a1286b343c7c8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:4f1e89ee745873fcedd2d79f185cb4f803852ba707567fa1141d985803b2479f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:1dcdaa807c76af3e075a358ee22d0404137fcd9562b6e701be12d9c258c9c2f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:a1f0978f33fffefd7c7b58d5ec9a2ed34b92b7340aabbea78abe6a8573ccb4e6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:f18671359e1046d33077fd8af448a0405a45289e8cdc267bdd1c64b35d94747e