Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips-dev, 21-debian13-fips-dev, 21-fips-dev, 21.3-debian-fips-dev, 21.3-debian13-fips-dev, 21.3-fips-dev, 21.3.0-debian-fips-dev, 21.3.0-debian13-fips-dev, 21.3.0-fips-dev

Index digest:

sha256:250af486bc7338b3ebb62dbec2b17785cc7186516259c2872507050a2bbdd2f4

Manifest digest:

sha256:e2e7ac4dc70001e46fd0b1d9880a2c2c17eb6cd8d13f08a649aad72e55d27ecf

Size

325.95 MB

Last pushed

14 hours ago

Vulnerabilities

0
3
1
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:371a36003e41314cb276883f7a59ae05444ac8d6534b0945b4b3353cd7baa2ce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:c01aff963ef47f6e4d9996ab93a1c805fc3878643c95850cef11e5c2f538899b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:a3195bf33ff97a4b59f98eeec04139fbcd0360d350e769d73aad2ded5000ed93
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:02078127fbce2e713aac035a1e08a2e050cd3c3dfdc052bc0af301d80bceab9b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:c7123f7a691bd8fae5d346f75c4eee882cce75740999738e5dc4a13c752ba237
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:c4f6f28221db76581d303879453feac89c206f2ddb325ccd67178936244fee67
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:1441c4904ddfc852036896a2d7870f48e493b02139a962fe6136c4e56823b516
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:5872baaed1d42f2a14fb6a1b0d3f29240ca455d13af962991dc15aceab964fad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:8a9101cb81baddd7e7ac0dca1aabc51bf576cebd0ca458b5d7b31e803abf56a5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:945eadf16e5ee9859d965d14b5b47b8cbe852fb14cb4693a63e4cf145830f81e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:04d88a1c20322f52505f2e749f2fe16c8878949ee6a40b705c07fabc6b0c799c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:5dc5d4b387694b370ecd0d9f7515e533aa790e94a1ebf9a8f3dcb27c68949b77
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:69c0f5a50085d9fe69af183e36c00a390e3603809a3d06dc0209e27c8279748f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:d59bdf124fded1f6847eeae4eb1f9916b1a6fa5b02b4be3b7470b5f038fac306
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:83855c7a4b1ef2d82598a83ea9f5a2c80f2d6bcb73921743c20561d8ba1a0fc7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:d876ae14984bc275dc5d1969222f4dad6df030170f70602d9d47d47374c743fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:95a0cbc80f43231cdd9e5cff05a79b223db636452a0bb73eb1b2fcdd57c3612c