Sign inSign up
Rook Ceph

dhi.io/rook-ceph

Rook Ceph 1.20.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.20-debian-fips-dev, 1.20-debian13-fips-dev, 1.20-fips-dev, 1.20.8-debian-fips-dev, 1.20.8-debian13-fips-dev, 1.20.8-fips-dev

Index digest:

sha256:5cd735c7e6f94fb41f32ba9e054620e3d04e9bcaf598ad44b18e987ed71e4b35

Manifest digest:

sha256:4ef1126ea1588abd4f66c204f58cd920c9ff72e1e75469f93e5ad6f4d5cc34fb

Size

373.27 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rook-ceph:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rook-ceph:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rook-ceph@sha256:511973352896e81f13c84459f4e8a328f319839584e14ffd27f042df40420bda
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rook-ceph@sha256:1024307ef8a0fbf4d9cf75c28ba3e4f60c38e764f70e6726ad0b8bcedcfbf37c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rook-ceph@sha256:77398506dd7d78f9ae9a4da9acfeade7604b550417693173adece2d5c759944b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rook-ceph@sha256:32343046818d19e4923eddd130c448302e316afb5889daddef4aa43c0d558473
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rook-ceph@sha256:e3ca02740ce46b8333f8d6aae6c09b23766dc8bf8a84b774f8d1cddb228f021f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rook-ceph@sha256:d904a9db94c6c1e795e5ea4a860a7f5468ac56ad261262328c589c50fc656a2d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rook-ceph@sha256:ec14221c9702db881f7fb23ae7856c6374ba40dfa3a9250d9d0c4786a0470d1e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rook-ceph@sha256:48b174f9e85342237f8eb3b28eb7019f6d0c3b1927a32498403cc4527ac6ac3b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rook-ceph@sha256:828fcb2808f24de7da006ac397478346d2669449e6b49049ec9dd623f2a3184c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rook-ceph@sha256:5553e665a2f5567f54c450af62c34a72f3334b9ca2a6f830e81837798813d313
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rook-ceph@sha256:429af4e6f75beb654bdc46f241f8f696109eb84ed7ed22f209f04bdf096d6dc2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rook-ceph@sha256:a57b1de4b2fcef18ec836be65e47edfb61304ac2c9349106a5c8861342bd7b83
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rook-ceph@sha256:3dcfd594a9bc3cb06060e18f3cd6d6ad432a66a7695022fb98a1660ab2965d97
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rook-ceph@sha256:b5f678390335839ed404bcea646c89deacb4c159c95fe439addfec3abc389f85
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rook-ceph@sha256:aed381dbc39dc2360ee55c0597a3efbd1efbaff608f77609585392ba5cb73140
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rook-ceph@sha256:547144b2560d96901bdd134e9846c85c0e0ed317e7826818c34fa8e077bc5cbb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rook-ceph@sha256:99aa15ca610d14091b0eead75690945a6c593c17cc283e6c91facc546f691fc3