Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.18-debian-fips-dev, 3.18-debian13-fips-dev, 3.18-fips-dev, 3.18.0-debian-fips-dev, 3.18.0-debian13-fips-dev, 3.18.0-fips-dev

Index digest:

sha256:884d3cda8381e8d7e4eebdcaedbbbced830ebf8b81188cd5fe73b86cffad5a57

Manifest digest:

sha256:62c89a910d693a98c1a277016f593114e1c7c148a6f4ccfc83ecfbf17896851f

Size

146.71 MB

Last pushed

10 hours ago

Vulnerabilities

0
2
1
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:e1abceb6b5ce066305567963ef89b23333d26846b628f862447e45939d7dd69b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:d7bb11f16b495e79fe1a66079736c1b1a17c9de70fd157bfddee077091c8e76d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cephcsi@sha256:1e3e21c53861a025512f28e5c383579855895589276c2f8f027fc8fde9313ca8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:99c116f75eb11ca4914f6f88c8af3a4a335902cf1cc2f9ce2af6615ac68e573f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cephcsi@sha256:13b274b585ebe15a58529b70bc03375adb24951b0d47af88ee9ac0728679dbe4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:2958f6aa7e2d3dbc97d6665d663b4cadc2c6a2b706f9d0c4ff349c50c5176028
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:69f33fc2adf38880694e73d222683948f5a8287e106072b530036975c7ff636b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:542ee7267e2ed9f13bdd8833f535abdfdc2e9bdf26931e6224aa4dec97d1dc79
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:dc56ddec5eda6e981bd945d95fa94d0c8c7c41b24c04d88aacaf942fd099d363
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:8d13834db9bd9c02875e4c5e78c6cf569ce30dda9dc6e8d859d8ee04506b2fa9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:7879471fe63bc7029aba9193a1f1e8832dbf0af2e25f0e3b132931edb388c0b9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:13fcdb1a25c1011038d775b403b4be1308642f3a1e5c076ec97c5753a356a39e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:358fb4181e914bb17478039238b10bccb3c346cb0c43da255c661af3a3a68e42
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:25132a4f0a6cd3b0c049313ef56b99361a50f79332fce69fdcf6eb344c6287ca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:6a7479bd9e7aa57f73de2977a2be34e404f6e5ca5746ec8b79a0a656c31544da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:a5c9bd5e0d672a824fda0b3d50cc8791a706423ddf5ef1df9153ee23661c946d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:4d2b244c21fc0416a4588dc90055ffd24f7665aff3bc28e66859359208b95597