Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.18-debian-fips, 3.18-debian13-fips, 3.18-fips, 3.18.0-debian-fips, 3.18.0-debian13-fips, 3.18.0-fips

Index digest:

sha256:1b6d72961e3db0514c0bf279bd2fadce8f3f94bee66a20698229e2fa04992851

Manifest digest:

sha256:a71a245fc080a2f7a2b924a0aeab1541261eb62875335aecef02cc0dbd2f9c85

Size

126.69 MB

Last pushed

58 minutes ago

Vulnerabilities

0
2
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:dc364807df8bb464c56c4fa5fb8925ef72d86cd0fdbba6b383326a353029b16d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:b14979d6d2505597432caa2802fc4267633dbfbbb6928a2abffebc4c0404ee2e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cephcsi@sha256:40c87e992f8d0ffa3593e76f41d071b981aaa60be303d8cc1dcd0ba30421e601
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:67adffb5e8379c5234c18cf226f021c521a87fafe62788f5501bfeff62273ef0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cephcsi@sha256:e122d30cc5ac8a94457c68d1bbecdfd5215941b962132234839a46c0305030f4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:f6eae4b833be05555c63250c559bc465bbc73e1d6b4c4951951a9e4e3ee70eba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:9ee3a28413c24adcc63364be2d3f2391d846139c1b4221e3dcdb855a7e8977f9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:a8be8d64491ac8f5b69eb707ea62d92b0d757899d724f30a3f862346c89e8183
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:80cb5f911072562263cdac5ff3753d3bc9dd626cccb1f3f5ffafa5470f7b0889
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:8f6ce0c77d24c49b9dfc5b323adfc84bcc1e300b56850bd8503e84b9043a5418
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:bd98ea8c8eada1cfae13d33f051ed00f0317140c81dbbad2e23524a629125cc4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:94131c10623672bdb1a50f58f887cc45d48166c060e2158a6a6c8609ffcf700d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:7fc0c5b66de5a6e3c60a9d789b43c3b9e9823430c6e5ba2525d278aa42f85cbb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:523226b55442ca335790173202e23cf7fba496e8fda9566f035390dec888d29e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:0fd391d979d37157d3ba721724a1433dd07919686611ee2f63a406fb3f26f1b7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:1e657238fe754872c171a43801899bc027ef4f981b49b739d3c1c4a94b35d962
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:f9404b465c8566a0c29a3491de5a36566d64e8e23706bed81af9eb895d0870e4