Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.18-debian-fips-dev, 3.18-debian13-fips-dev, 3.18-fips-dev, 3.18.0-debian-fips-dev, 3.18.0-debian13-fips-dev, 3.18.0-fips-dev

Index digest:

sha256:1ead4f26251f6f7dc2f5d90e939d4e5be17965ef8b062fa7e61fc04eb1adc03f

Manifest digest:

sha256:6612c4537e3e2fa269118f1402c3c12ee7d0d8d70f583e7d91d88d0f11504b82

Size

145.99 MB

Last pushed

13 hours ago

Vulnerabilities

0
2
1
2
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:ea3fd0890f113ee0f9e1253d75ed8b7e1ab8e6b2fa9169dbf20a5fb570f65cc8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:74e2ad90f8f2d601ba9cd383a782e1628df9364e480a0165abf92acca0d95eae
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cephcsi@sha256:33e67921b4b2f50b4525075e05cdd6466c6a92faebeecfac5216d3765176c797
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:c0f89f3e9b26ed5b1a3fa9fea578f8953f66c12e278028665554277111a5bfe0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cephcsi@sha256:42ce22d6d76a3326597d3301ed5db77a12f034a46bcb45c1a9a7b519983a1ad8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:fd2388eab29ad8e69d3130c91b1e6fa40935a9d10039f6be7d801d3cb2a50ed3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:3284eb4caeb696a13f44c64240c1b594e1807f08700a0f6ec2e2f474d18f633e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:62997aab1c152edb07573501d0b49664af0e436b5606c4dd425e3c4d5cd44ee8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:046346896160f010ef8c9b754253021c64378a7a07a92a22d5cec200bee6740f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:e4836ff633e653756a23e9c3136a987045210881ed481c54f50de17aab08ac30
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:b8c581a3efe142a8abeff45675fd051c237aba327df59f6663cf856a9f72250f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:1665958c056186ce5649af57b1a404e5c51c06355c138a879b8af8b09adaf602
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:f2342615594a02c829cc562d09ba567104159bf3ddf0921688c890fe5386bca6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:2aa5efc66747850a07edf844f42eb6b25d1279748606b1ba8facd0a670cbeb76
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:a266b97b69ad9d14edeca79623087559c0ca8ff62883b634641e604b2352e840
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:dc3e653f92db9743fc348fa2d27860dbe870bae2105480c9ef05ef8384650a62
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:9559212de3243b49fc4f81d2bddb28d89c32f1fbe5ad3d0f393f8e5ff8c046c7