dhi.io/ceph
21-debian-fips-dev, 21-debian13-fips-dev, 21-fips-dev, 21.1-debian-fips-dev, 21.1-debian13-fips-dev, 21.1-fips-dev, 21.1.0-debian-fips-dev, 21.1.0-debian13-fips-dev, 21.1.0-fips-dev
sha256:4c24f31d19289f031e9cbda3f2671ccb01026ddefe6e43389bef6601512e8b4e
Manifest digest:sha256:7e7f5b656228289a8b8fb423b0b8d53c1929ea2256fb88047ac88367410a0e6e
Size
326.87 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ceph:21-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ceph:21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ceph@sha256:ee72672c202cc89a2337f99825d07d15904581dd54b4b58190b1e1303e4895e0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ceph@sha256:e775b82091a03e4bac317320f018cd1fccc48900d8ec217361be6abb4f706ea9 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ceph@sha256:66a6f3c7ca5940e64d148c7043eb5c59da0a11915e6090b6b34a49adb2bc0ad2 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ceph@sha256:83e296c7baf5b0668819a6550a92f285b948a006c27bd0a30ec4d6622e2b9372 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ceph@sha256:f80949e28843ece1def315e506f28695f71a7298b5fb2897084b62cd52d72bb4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ceph@sha256:41d2dbed0ac895e5eeaccf355e5eab2c82d4798b2cf3e23b507a487bbf45bee4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ceph@sha256:716235d8c40c15b30d1419254d5d838d0a9b627deb064ef6b15a1351ce9b8676 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ceph@sha256:57c0c34c0b225cec4d32acb000788e65895f3c5fab359b4a49c41beaa1b57481 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ceph@sha256:16668fcbb2c6a362f5093cbea48d720e3ce9f491adc4a8dd0f7aa229c10281f6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ceph@sha256:17f08f11a147e2adc1c8e89c11dea61705be1c71762ad40bed7a0d43ab7b40df |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ceph@sha256:1691277b4e9952aca842d2e6bf21a58b4b356437469672e0b1a2ba339dec5011 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ceph@sha256:dab7f14bdb363064a40f7094ce6517a5906ec91027df7393d1145badb10fbea8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ceph@sha256:18bf4fb473ff45cd6c5fddbf44bf52f4f70ab7bfe703cff6c9937b1bf3a2caaa |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ceph@sha256:c2a0088039077a2a9537528033972ff6298730846d0ce3b617c3d3cd1d338a6f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ceph@sha256:53ac92ce903f9ba80d086812984aab773ad462a2a0f58af463c7e590d582f6c5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ceph@sha256:96eae411cde7c8b0579799eef8aa533b4ce111af847c96e14934a02a4d183b83 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ceph@sha256:516ed421063940e1abfdc0a8189f2ec0c0ca6994dc31f6229dc61c04af42f869 |