Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.18-debian-fips, 3.18-debian13-fips, 3.18-fips, 3.18.0-debian-fips, 3.18.0-debian13-fips, 3.18.0-fips

Index digest:

sha256:5c07fad715823fa717acb9c1e1d4f9c6b1b87d902b2496f2dfd678e76ad12d0d

Manifest digest:

sha256:cd31a4343ff8438a98671104144e95ca532fae807045a2c96e976fc3511e2351

Size

125.94 MB

Last pushed

16 hours ago

Vulnerabilities

0
2
1
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:ad5cb902fa79ced29f00dbac2d531e172acf3e41bc2f3379cef6ed1774b7df17
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:b3eb966635043e3cf115ae8caed5664d1edce567699a027e10888132d288be2e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cephcsi@sha256:ede3e7d98c7da502fa92c1fcff9775935a0d74aa426bf160666dba20d1e8377d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:2b8bdf8b82d5bd96548b98ce2b8580a2c35b18d734dfb3c38a1025e4067199e0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cephcsi@sha256:3c8b08a29223dee41a18da6de7721f74d30b434d44e49f568bb3eef476a9ce97
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:0ef24ea592e724734bf43eff8fb4e3fb148f1a8462f6abafb4ced0e3105bfdb6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:bb85ff1ce90e87c705de4e1eeca6fa145b50645f9e87c4e06640f4a40a78e1b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:31b5b7e5d64a41eeaffbfc83e8ab22b5e925bafb791831191ae5d07e9dbc3f5e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:9078fd38ea00609bce8f5a150791a129bfadea2ee67a26a19028405b4fbf8fe7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:b85092f9fe3c37d1122b61bb03f85bbe223441f542c0d93f6d31fc0745333c47
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:b5a348ff22bde262d897abc795b9610488e64f9a93b1840f88dd7b4684da7e9e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:402755962e773b687e40d05842f039c7b368fc78b831de3be12ee190198a9e83
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:c3762c5bdd9a72c1858f01ff649d443d4086c817f8ae87ad20b6c7ebdec76a82
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:c99f44d53e8e77c0f280baadf8119ddc30296c7260ac735b2a0955829783813b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:50b7dae1a7af689bd4acd9f43baa28b4a3ce30be734e2e375ed2e3be7b8d2280
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:b1405b2d9f46030b9d8aa3532ef14de2511b63f7c602f187cb892d89f6b435ff
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:8257d04bde89bfa006d1e79e6c172ce8888905fba74191556e3e06a0fb469a3f