Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips, 21-debian13-fips, 21-fips, 21.1-debian-fips, 21.1-debian13-fips, 21.1-fips, 21.1.0-debian-fips, 21.1.0-debian13-fips, 21.1.0-fips

Index digest:

sha256:1fe4c02107c7ab29983101677a27b7c42a4e4134d68eb656e52ec58118eea2ec

Manifest digest:

sha256:86762febb8a31ad12fbb66d7587decfe60b9fe75c68edfce4c6ef775eb71060d

Size

321.80 MB

Last pushed

19 hours ago

Vulnerabilities

2
31
12
27
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:c4056b4785d2e272f69dbcbbc17e214515abddf3cbbd942ac0034ebd2c0dbdd4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:ab546e8560806005f142a3adb4ad648da05031a582356c50590baa8ee2dc1c3a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:07436ad3558dc6ab10ca9b1775c09516632accf710c6db853f92a2849197c139
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:52a04cf486d12b023f7ee1d962f12fec34781f46e9bbd23fc4f5287dfb138fd6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:32e7836e5dc3eda2a90026537f943e4597093424da6e0c864a70f002277b92bb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:48ef9c620386473c830289c0f6ec399a1ecbc14b81b2c601d3b6c2af1c672092
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:d4f44aada835b38410282797246008580311246621d78f013bb0761fcc0f4f41
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:575d5500dabf7850d91af8e006c21bdb98d7d427b753ebce064a65320d5c90d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:b670f77712f2b7cb76562ce0390da1708efda9667af375ea7f9141340b8d68c5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:3408ed3c0798e687db8eb72580b5940a6f19d4b812ee4e9161089e0ca1dad6ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:9b113e2ad9da014dcee93e7b050fc37575b6d19a9551fde44843ddc3f1098971
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:79813f7d8793123f859ee80045aa469240d56d217e0c137182d04a86c69320b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:06a9fdc9bf2a58f3bf0046e9feb075701974f2169df9a552cfdb83532dc8de9e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:4c6878babce2a3c509a91c18a02becb86ae54da887153fda4e216cc664ee7613
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:74784ac79e05a375b49e8684fc4cbfbc2303e1d6140dab06d60a1de77653bf89
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:b9dc56762554e3d39040b8aa93368ba8ac7f7dac0c82830a15e08aec435f0879
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:27e94bca8fd500706b647d6ea4d944ddf10fc4fe82eeb1769cdb3bae2752cc7a