Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips, 21-debian13-fips, 21-fips, 21.1-debian-fips, 21.1-debian13-fips, 21.1-fips, 21.1.0-debian-fips, 21.1.0-debian13-fips, 21.1.0-fips

Index digest:

sha256:2a24b6d820969e52e58cde0528b391a332e600206ab80eb6694fd23ea7d4f888

Manifest digest:

sha256:4efa50dc85e2b8411ffb18a3b5f2fd1dcb0acde4ca4490aca62a2d84fc070523

Size

321.82 MB

Last pushed

14 hours ago

Vulnerabilities

2
31
9
26
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:01c18e1b54430f4bc683be45042016975a6595c433ca8238828dcfaf8657072f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:2589b9b323e88f5c02da3590fb3283effd67362d7d1cd8062a239edba8d49242
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:0f2159afd7e3feeb0c1040f479bbf3717bbec0917b42f982ccafd52f48cf04af
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:31db140601b30f02ac1f7fb1ec72b8139080709aa15d94e9f6e4efbd6c94d9d3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:7c8144f45a31ad6691fb6f5509758bc5bdbc2dd2352c76878438036cc27a7299
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:a345ada4aec12e6046d50d1b024c69949fc0308108eb170295145c3e6ad09f00
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:3705e3a2a20e3f0ad94c40711bd896394f260d30deff319c03b5d631b702dbfb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:e553320713afe809c4ce3802e477bb475f1dd786c79de804c5be61b5465cfa9b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:44553475b8d93c96ece474c599546994d22dc54fa1c24e5db07b9cd2d7b6b286
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:949ff835b6904b1ad34ee385de910e017ea1c94004ee5b3c16759219cb6668ce
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:b2f1089ab60f3e292f358486e8b792c8b603fa8f3048da5a2ead1deadfea1839
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:e94797133f4aeef4095ca8763243b306c31c260ace3d82d36109bddc68ac13bc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:f788f2323d2ca326c85098fbb643c7853761f026a78c4d2d748e4ad09ec6cd1a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:b9b6ad500c9a51a2bd4435585119e70f3692d02b9c30159a39dbf8a8e610a508
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:79a21c8d8aa4fe2f43920349126f0374755d4a8f525e09736137906ad2f12d0d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:90295aa00a43f68942a0eb5c0f59633248c802b622783cd59f12a05b24261851
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:75ad45c3a5d811e5470c6320c2c3809cc155b67f62ca7c98f2ee096b50f073f1