Sign inSign up
Ceph (Rook)

dhi.io/ceph

Ceph 21.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

21-debian-fips, 21-debian13-fips, 21-fips, 21.1-debian-fips, 21.1-debian13-fips, 21.1-fips, 21.1.0-debian-fips, 21.1.0-debian13-fips, 21.1.0-fips

Index digest:

sha256:4eb944ba85a9b1282359bc930a2ebc63566487e9257465d464b5241c5ee490b7

Manifest digest:

sha256:ef61c94fbad84fdb358420cb74c012acf8dcf6442d444b8b5438d6bff33c6baa

Size

321.82 MB

Last pushed

11 hours ago

Vulnerabilities

4
34
9
26
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ceph:21-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ceph:21-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ceph@sha256:35bed3808c9834e8ef1712cf5759b693d100efc945cdbbee9ba575f084030792
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ceph@sha256:0b17b27ea3c75db29259ff73be4a4fe3e7e25af3ddaf194a90dc28a6ac89d18e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ceph@sha256:216ce6dc87c00e63c9406bce8b9da7e9938ac59b09ed13f8bda0b74cd4a82830
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ceph@sha256:039665a795b43d741c90301d3d4033d7d008ae25bfc3c5b34679610e96b3fe35
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ceph@sha256:e1afa50b4a757b4f43510adb326bfd41211c76dba13f3353bbbe6c89de5907b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ceph@sha256:25a1422da837df167235c601cf895d03e0fb61d01b16d68d919fdecedb33adeb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ceph@sha256:dfed1be41d06e3129e93a938c01790a62c2881c9b29b878a6d1473b0c983c112
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ceph@sha256:cc3aa260646b07be3158383ca4bbee704727fff2299593210bbbaed082e73345
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ceph@sha256:9addc581f4f605cc9a2f087c48453584d94f5e19a5438ab820621d873bd407c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ceph@sha256:55bfdf5c14ee418e11c19f5b8a47163fdbe921cb13ad0adabbc2b54ea04523ba
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ceph@sha256:54532b000a73b45690268ca89832bff70f7fbdb6b2148f6cd48c1aa90f451e16
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ceph@sha256:e772dddbfea0bdc0249b6433bf7ba35affc50ca246ab462ba68cca0e53c02721
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ceph@sha256:924bd72fc4d19136ba59c73444916df86d131ae6e416b31f737014e52b2a4340
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ceph@sha256:ffa1906aad475619171b066690417d73d0db0ce101907d3cc02da92b0b9d867e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ceph@sha256:beb5dee823f108a8d7c598ec97052e2c8dd367cf1be802077669df3b30db1b7b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ceph@sha256:c2c0245bda430b9d2697c2ef6ee8adf476368baa39c4504b08d677d883df6e45
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ceph@sha256:10120fcf9e4d0cc92baf044890b7c17e9720e1d2bad9b17174f61854a3e69bba