Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips-dev, 21-debian13-fips-dev, 21-fips-dev, 21.3-debian-fips-dev, 21.3-debian13-fips-dev, 21.3-fips-dev, 21.3.0-debian-fips-dev, 21.3.0-debian13-fips-dev, 21.3.0-fips-dev

Index digest:

sha256:5957229c41ef1fa272a157183658555d2296eec58d88a15d5202f3ec78eb72de

Manifest digest:

sha256:1a55b8a0ed9b6d164dd265637a93410166cdbe4c8fbbcec06979f426e4a9d2c4

Size

325.88 MB

Last pushed

10 hours ago

Vulnerabilities

0
2
1
6
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:aedc53d768c74498079bf830973dc275ed05965fb7798a9d63aad11621a4aa96
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:9dad7cb2a992b42ba148882af7073ee2c14730b3d8028dea2e23028f2e79e640
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:48f77020a82f783628c2d1bfea188739b1989e92687f139aa94942ce89f85da8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:310142597d721fa5808b5ad4f11be5dc61b704c5db8fa9265e71ed93ba979f16
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:e28ac8edde6ac32fc46d205c043f9b3a8dd7ffccec241a82f5109723162a1661
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:12f357adcf90e55127798dd7591592d55e7406acea88e059f687ebc5aa71daa1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:e436b9b0712a3b39fc2d9b35abb8b6a417ae239ee1136b546da6877038bfafeb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:0237f4be99d9a2df2176a1a62c0926783632a18ec8ce962918a218fef96af7aa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:61bb3c2b96a8abdad0eea257822dfa7674cf6724ef7919f9056202c07abc4fc3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:a7d6b7e6a3da349a3c2717735579d6f307e91602ae27e6d9c8a7d7a2a6a106b6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:6f10379bc898d58e251df9ca75a5ea7f3d98f39c16351cbebda96c34a7649a61
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:5877aac67f52239b735dfd76917d58767d5bbdd4ff4a34c6c83c9edcb0b85698
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:3f9ab92e87967d721f2ce6e3bd9f4ae1ce67944d34682637b8c9c5388e93aeca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:857ed4ba60fdcdfaae24bf5437a45570b2ae447e1150ed6ea6c083ad5100d150
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:87ca0ee1b9e8b8b52301c5a6ccc706e2d96eddbd157fd92abcadc984a7aec3c2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:31c433d33881fc27f46b679bf9ad61af3baf3affeada98c648a4ae40c5ecaddd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:ea352bdebd8d2100e42ad7cec810b81c8ff810dd402f53469f251d1b1f68cadc