Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips-dev, 21-debian13-fips-dev, 21-fips-dev, 21.1-debian-fips-dev, 21.1-debian13-fips-dev, 21.1-fips-dev, 21.1.0-debian-fips-dev, 21.1.0-debian13-fips-dev, 21.1.0-fips-dev

Index digest:

sha256:4c24f31d19289f031e9cbda3f2671ccb01026ddefe6e43389bef6601512e8b4e

Manifest digest:

sha256:7e7f5b656228289a8b8fb423b0b8d53c1929ea2256fb88047ac88367410a0e6e

Size

326.87 MB

Last pushed

8 hours ago

Vulnerabilities

2
31
12
28
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:ee72672c202cc89a2337f99825d07d15904581dd54b4b58190b1e1303e4895e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:e775b82091a03e4bac317320f018cd1fccc48900d8ec217361be6abb4f706ea9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:66a6f3c7ca5940e64d148c7043eb5c59da0a11915e6090b6b34a49adb2bc0ad2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:83e296c7baf5b0668819a6550a92f285b948a006c27bd0a30ec4d6622e2b9372
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:f80949e28843ece1def315e506f28695f71a7298b5fb2897084b62cd52d72bb4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:41d2dbed0ac895e5eeaccf355e5eab2c82d4798b2cf3e23b507a487bbf45bee4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:716235d8c40c15b30d1419254d5d838d0a9b627deb064ef6b15a1351ce9b8676
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:57c0c34c0b225cec4d32acb000788e65895f3c5fab359b4a49c41beaa1b57481
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:16668fcbb2c6a362f5093cbea48d720e3ce9f491adc4a8dd0f7aa229c10281f6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:17f08f11a147e2adc1c8e89c11dea61705be1c71762ad40bed7a0d43ab7b40df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:1691277b4e9952aca842d2e6bf21a58b4b356437469672e0b1a2ba339dec5011
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:dab7f14bdb363064a40f7094ce6517a5906ec91027df7393d1145badb10fbea8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:18bf4fb473ff45cd6c5fddbf44bf52f4f70ab7bfe703cff6c9937b1bf3a2caaa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:c2a0088039077a2a9537528033972ff6298730846d0ce3b617c3d3cd1d338a6f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:53ac92ce903f9ba80d086812984aab773ad462a2a0f58af463c7e590d582f6c5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:96eae411cde7c8b0579799eef8aa533b4ce111af847c96e14934a02a4d183b83
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:516ed421063940e1abfdc0a8189f2ec0c0ca6994dc31f6229dc61c04af42f869