Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips-dev, 21-debian13-fips-dev, 21-fips-dev, 21.3-debian-fips-dev, 21.3-debian13-fips-dev, 21.3-fips-dev, 21.3.0-debian-fips-dev, 21.3.0-debian13-fips-dev, 21.3.0-fips-dev

Index digest:

sha256:7375a5580384491aeb6f461a55c4c485a3897dd7469a07db9b0f615b80741b07

Manifest digest:

sha256:9c21fdb4e4627de3d7981284c509ce122da82711fd4cd328c29a11c4e515affc

Size

326.01 MB

Last pushed

16 hours ago

Vulnerabilities

2
31
12
28
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:265bffaeaf65ab630486ad4096a79a1c421c94f5a5e0552a51807365e80f2dcb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:7ad599af9672d0a83be67e783592c95b3b9061507454a4c1c9625441498ae0b5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:9691847b9a40affc403cf874f8f958654d94de0cae4678eb763f779873328e7a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:097ee007be628f0463ae8930e7383704ef3f64c55bff98c12e335f0a3f9b6866
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:3849615335d821352d645ccceadbfbdb79da7aeb884238e25a3ff6cffafd9907
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:2e0e121752ed5195415ee09b53e436ef3446cf53c3bba7072f7ecb67ee72a72e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:6f9b781a900e4e7e31d936304d29d77d657506dc885221f518775ae9a3ba3ec2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:789703ef2789c35d4eab684253f8036ab79388d74cb6e2c359c68db9994bc3b9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:9342ab13c0d925f91e01f07a892429c87fd8c715ed5a65c44c0f2b6eeb5a7905
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:1452fc52ef188b6ed50963eb3273ccfef19503d29865dd1c72189bc1ec537c2a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:691ee84b9b3381f94261fd97c755f95f913aae4785fffeef5c6c94fb38ac9206
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:d3baee835ab55d5e5bd9e06ad65ebaa8a57bdf30ed0466433ff495ee3d48b88a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:4387047135c03ae21ff9be0c8628f80f7073e76ed2fac06d3f1baeb72c6c6db2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:b2471861c0eaab15d0ce5e8bd1e014d750dc662ce79ed0eb2032a6ce3a6ab1eb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:ef46785f58b8cd40bfc71459d23745a64a13989c82105cdfa03fb2f4a6a6ecbc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:744e2cdf7c390503124d0c93af07508c9bb6351230f6f0d1af80b8ca2c108a98
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:8f221f3d572e16ca1bc2526d31799946d913e3b8d8ce076929fc4c16480464e8