Sign inSign up
Rook Ceph

dhi.io/rook-ceph

Rook Ceph 1.18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.11-debian-fips-dev, 1.18.11-debian13-fips-dev, 1.18.11-fips-dev

Index digest:

sha256:4e508e3b22fdd567b31436dcbd26e9d1cfc4055a47aa9a8f91ec8849c62963c9

Manifest digest:

sha256:e65db4001348994efb1ff86d170b2425d7e45e03a418777ff5ad01bea5aded4a

Size

357.37 MB

Last pushed

5 hours ago

Vulnerabilities

0
9
5
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rook-ceph:1.18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rook-ceph:1.18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rook-ceph@sha256:959f02cdeb14bcd3beae1008299811e2f93d003968da68043f514a46d15a9ff9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rook-ceph@sha256:ea965a09a26e592a8d7d5be17633c824a62a2ff916c228f8974102df21b0454a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rook-ceph@sha256:2dfd1b60ae9a52e61f8b8e206eed1a1b2caa1e0097aa63f04d73e9946088ca6b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rook-ceph@sha256:c35c34c4b24ea26ec28a3f4f1beb4c2fd5321e9eb73c67db9c817b21df46cb4a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rook-ceph@sha256:e04e9be860dbf7b03d8b5f493966d0cbe5fd5e77ea76d11377c2d79eb2ffb93f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rook-ceph@sha256:8bf20529bb86f775149852ebf48f3cefad4ca5e706e497a4b425df069876aad8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rook-ceph@sha256:78e11927c3edb77b0c66e28f6006b65de86c0881d7ff81eabddaae72b960279b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rook-ceph@sha256:6accb97b6e0893556fa9b1245278e5abadd37e29ecfa375b3e243dbe0d59bf88
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rook-ceph@sha256:3d4a64d722196c384824532d605cf65bb658ee3c8260929dcfee7278a3905aa8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rook-ceph@sha256:2f3ac4abc12fd04de41459338500ed1805154702b97f800b3dd5d86ba800c622
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rook-ceph@sha256:627fbae42521857f64be40e7ac4215f3a8ec38054ca87d6083e5c97751a01478
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rook-ceph@sha256:5f483afba34971819abc78f738ab08c3777d4ddfdf0b3b365226261331a9eccc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rook-ceph@sha256:f5d1d3f4cfc2dc20bffa3bfac2e9f9643e8e58e585e94ba3cd1e6acde9c6b46b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rook-ceph@sha256:c2ee61e06751c104ab6cf01515f57fc9f8d115cf5ba9c70fdf0d0043ad64ffff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rook-ceph@sha256:de4162fe253313cd7f3985441dd69574d1aa0e7815831d5cbbfbd9bf80cfc552
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rook-ceph@sha256:3f4082c895d842fdfab2f4c71a9587c3af556de9979011d0eb0be9deca1c52e2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rook-ceph@sha256:bd3f614dc3bfcbec0d7940f517bfef1f990993a1c90964148189fc4dc00162e6