Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.17.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.17-debian-fips, 3.17-debian13-fips, 3.17-fips, 3.17.1-debian-fips, 3.17.1-debian13-fips, 3.17.1-fips

Index digest:

sha256:1dcd47d17bb6ead39020654c1cf75a0be5cde26e9f9e9e9071cad292e8c25b50

Manifest digest:

sha256:e80e230af745306a651af05bb462ffbbc67ba97028e90f31aaae94c0a45f6eab

Size

125.82 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:b9ce8b03ad5a9bd396f28f40f972b86f0ac7bfb634b6bfd78f4fb83a6ff060c8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:5407a476734c41d4c7449546e1799e1673721571d50b6654dc49e531b393e93b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cephcsi@sha256:357505ab20db7635c1fb9c923749b3e95b389ed14c93d3c134032f0521891eb1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:88f1880a8262fad041e861005ba4d754512597a3a8db4d0ac72779dacd60f045
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cephcsi@sha256:df186e841cb0e42e500b168a98537beaeeee9e141cd8dacacac00bcce7fb2d06
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:8a4d149831729f1c6028f7a4c484c6e4ffd9c75dc9c993eccd1fda978ae2da69
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:afffbf32597828b7c13bb4d4344041ae60f4c0ff9db3a0534f3e4de1660d95f4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:0a6653955642d936d65ce93b0dccfdf9c0444cef8b9c9eace8785a855c6923cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:db6e40ba66f458f15d68da7045bfcbbf2d4bdee79dacae7bc45357c349d4689b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:1fdc20c28ddde82f085e742c9fe7a67901f1913c6d814d842fd994e383593c7c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:d3618ee21a63de156368a95e8cd5b5ab9db244047c2ff94f9e4e7f2ea47a139a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:2465ee8663973c46dfe34ae26dbdba21900283edaab1290c591f0cd4ab92991a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:91b459f3ccbfd3f06ef266e56739ddb541c176891b7fdb1e885cf06be8c6998d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:dd5d0a26bd34ff3fa50489060c08e99b553fcc7e2b29dd634b1eaac5de008d77
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:ea61fcd44408b32e217baeea7db2fd8b49428b80404459e59afe1156db2fac00
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:3e1f220c6848948976239beb7340b53d4fe85ff6c871de62ea0a6889df657e51
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:7385903e64f57d02dbdbcb0a71e5704ffc66da33724b178dfe52555f21b62cfc