dhi.io/rook-ceph
1-debian-fips, 1-debian13-fips, 1-fips, 1.20-debian-fips, 1.20-debian13-fips, 1.20-fips, 1.20.8-debian-fips, 1.20.8-debian13-fips, 1.20.8-fips
sha256:70fa17ea0093238382a86d94f9ad1c89094909d46ba32622fef35ffbe0387794
Manifest digest:sha256:69ac5583914c1541670edea869a467cae953d85511e699c78429d718c76836ef
Size
338.97 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/rook-ceph:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/rook-ceph:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/rook-ceph@sha256:f669655f9ea366ed9816ec4cc4ba3768cee3934f50e46ecfc6720373f3e8aca9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/rook-ceph@sha256:2969f8b7d2ae29691a712833f99b614d9152a17380c893287a112b9edc65460b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/rook-ceph@sha256:01a4cb40b9bb2a99b1729fd3ef091f16c4323ec44be62cdce6b32ebf8e51debb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/rook-ceph@sha256:4c32d30179c5bb7b664810986960fc21f84bccc804db6af9aa96e40fb83c2b8f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/rook-ceph@sha256:e92bff5b1dec1db5909dc3373e22819b571d40b7009a21f035b459ebe8e2338c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/rook-ceph@sha256:1b079593505877e1e903ef79b1a51a1590e77870329e9d2ddf0bfffa9f84c2f5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/rook-ceph@sha256:f4529753f5bc442e7f0b650a6d8e96946b9fe086b09ae738e5e184279531b576 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/rook-ceph@sha256:55a49db1ec62d5efe285d4ceb782958fc27dbcfc3918b43c9fb35af8e8f2888f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/rook-ceph@sha256:28756cb4517f5c2fe1a3fc016225e88175e74a314187f74c712d0c6fd5cff0df |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/rook-ceph@sha256:d169948d044eea2f87b178f41178adf65517fbbb3af857916a6246cd92b576d0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/rook-ceph@sha256:96feb93e39f8511867a29831630d9da6cf18c3b4a44a44460b9f8d04973d9311 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/rook-ceph@sha256:7b66b225a645ee05e1f885610819070a005839a26122ea12644929606d04e697 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/rook-ceph@sha256:cbe9342c178f1275beeac4ac6e1fef3fe52f494acac2a65ae3a02d8ad1027f79 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/rook-ceph@sha256:131d1a51f55404ae8dbfacbdced6d6a3fdbd9c47c6584c5f949c9afb8839b222 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/rook-ceph@sha256:1a789fdb9d22b639d437f692c0f1a7a220fa2951f0f6904f7ede349b5344ca7a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/rook-ceph@sha256:3b98be0a59608739d1562dd61d68fe883f9405eb8c5ec6fe51d7f0032c7f9ded |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/rook-ceph@sha256:f2aa566a7f177dbcada928ea8edffbd97147bf5e1df062f1dfbc2f26ccbe7471 |