Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.18-debian-fips-dev, 3.18-debian13-fips-dev, 3.18-fips-dev, 3.18.0-debian-fips-dev, 3.18.0-debian13-fips-dev, 3.18.0-fips-dev

Index digest:

sha256:c0dbaf1aa3d497691f37fb5a48f6e330304ceab5a2a6fcac15bb8f270500875a

Manifest digest:

sha256:bb0ebd0574e62ea3a7d5626e2bd60a5115977cae6edccd8b567661b6dcba5823

Size

146.71 MB

Last pushed

1 hour ago

Vulnerabilities

0
3
2
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:c85bf9d19e27ea9cbc24165615a29f26966c4bd5929cb9b95e4fb8fe97d90d8f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:e36abd413df4dc25afa08d0aef4383a653f06379494239fee3598f9b0fc177b8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cephcsi@sha256:6399c51c80de3dea8acb7c69c33c010755fef72290f80e84341a5eacd0aade12
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:0d9d63c982dd0df7105445189d30339a91be4eee5c8f2d11290fd140960cec79
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cephcsi@sha256:9da3133883cc8a0d5bb8b8c45a56dc12813961cee4328ab5dca60322191b326d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:8ae393770d74f4ddb71881f5eaa8e4c8b927033bd03bcf70fd0a905456d7f10d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:74ed21ab725bd945e2fe306895bc55e9017e93a9a1b7d738711acdc014750f08
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:00e8edd0603dd1268c3b4dd25bbf6bfb24a0aca85a3c803ca53b65b5a70e0a56
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:17450aa3324f76c7f62f94633f947f581719fa422bdc6181170318a41d78902f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:6bb25bbd8dce4f6aa5fb945634b59a4b9563653efed149e49d7cef52da5e54fd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:a8825c4bde0cd2ac1901a218dafdfbd1fddd5810df62ed4c2608f0a899ec0e7c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:e76fd4631de2d73555ef9dbd46621c83a96db1eca3f17ed85d45bc83db4b3a27
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:a030a7a300310fdf88da73ca0d23d98b1a2c92313a78c7ae4f1f231682693bb2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:08f9cd3e40daf157e940f12265531f3e63c0548b93e5bef442e9ebc27b424328
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:488a36241a8cc6c543d694643802958f9c357ba8037a5268f02df8b219a55a6a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:3fd37d545bb668ec45e37e3d2162a40ee6d545a88fb15273ed55db57652ca29f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:161f410fd96ccdb0bf2bd273b77725b696f7bcec5185dc7a7661c4615843d403