Sign inSign up
Rook Ceph

dhi.io/rook-ceph

Rook Ceph 1.18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.11-debian-fips-dev, 1.18.11-debian13-fips-dev, 1.18.11-fips-dev

Index digest:

sha256:9343ac2fbe4681cecfc87ab5ad95c424d3a4f0c78f5110e60f7074e4bd6521ab

Manifest digest:

sha256:36e2c6fef2d544d0ef9ec801f3814ecb81c149ba1098aef4ab0f12206a27dea7

Size

354.78 MB

Last pushed

10 hours ago

Vulnerabilities

0
6
5
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rook-ceph:1.18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rook-ceph:1.18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rook-ceph@sha256:ef276bb35c1a2f0612bf5b08b60c7da0a014665bfbe54f17dfd0c764cf18ab76
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rook-ceph@sha256:292b0aec8d00a5a7f9f920861197438850f994828653d7b9a9d21c1b1872ed1b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rook-ceph@sha256:0d6aa9f80c53ee1b79e991f92351f1ff9b2b4cd12175d52af8418a0bfadd6c06
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rook-ceph@sha256:a244a0706b49b79ebad811fc324bfdab006e3bba3df1582d0b9ab81cbb30803b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rook-ceph@sha256:5c5f55c67344637553b3b3bd9600c647ab53f3b8db2c51e7804ecddfb8817233
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rook-ceph@sha256:fcf733e9d949efb0ce154acae0a92ee55eb04fd208b0d618f63bdf77b28d5dbf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rook-ceph@sha256:5d0cbc4cde55671d68b73079528c5492952f655077e184035e74e037fa2dd0de
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rook-ceph@sha256:78f1af3efd711e1e07d16a6fd8edea1649330f8b961f3c608b16ad848a9b8f70
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rook-ceph@sha256:ee7567f01f5c185726da28ccc1edf0d983c98ea5e86282badc66651c0152bca7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rook-ceph@sha256:2f1ce54f7f8277d059a5775bd7517585616fb3ef87757254ab628a1eddaaf2c9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rook-ceph@sha256:c35bfa41c557cb7f5cb3b1c818b0602626833abc3a85a67a9d5be0ba046bbe5f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rook-ceph@sha256:99ed71e768192623277cd735ee12338c8f06296d2dce1c85fe37a65c00a86155
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rook-ceph@sha256:a4a8dcc01ac343840ffbd95e7cdcdc70430b2d16db125f745a1fe750425c1f5c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rook-ceph@sha256:c1e11c8f762327177c296c5ce759f24a939d03892e03018239e9de289513b7c7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rook-ceph@sha256:170597471ca07ad9df6256f6a926ad4161ed55c2ee1b9b36bd823cabccafa48a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rook-ceph@sha256:0f65f502822ec7a9592f1021f7e57ba37ad1344ce7c4200e926c39dfb2ad597c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rook-ceph@sha256:46038e0af247ab40ba2f9d62c302a6b9eb9244af31c83c0f9fc89d8835714f74