Sign inSign up
Rook Ceph

dhi.io/rook-ceph

Rook Ceph 1.20.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.20-debian-fips, 1.20-debian13-fips, 1.20-fips, 1.20.7-debian-fips, 1.20.7-debian13-fips, 1.20.7-fips

Index digest:

sha256:e5ece227892cb7b035ae81c9ca2718d30719a48b05ea19416c0be02551e9cb61

Manifest digest:

sha256:b2b474f79e39062a2b3334eda80c4742b5273e60b8458fb7397de6a7b7fbe6ff

Size

265.73 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rook-ceph:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rook-ceph:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rook-ceph@sha256:aae71f36bf60c70d931f011679cb03623292a64e9cb69f01e72468cf74bcf925
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rook-ceph@sha256:21fbf27d059883bd69ba5a13e0111381305966a8d337ceb6a4aebbc06af86090
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rook-ceph@sha256:75e13ec02babac3eb2b9726768fabb18f6ccfc953457de0a94c5c0e1214a5157
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rook-ceph@sha256:2efb377ac45559a756a17f7f1da27c0a01b41cf350c6fdc3a897a95a0af9b5c8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rook-ceph@sha256:0382dd159bcd5878b1e5fc906983274972fd5eee3dfe85275c3b9445f3207f20
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rook-ceph@sha256:cdfe1e5f964222efa4c0f1a4e4a8b583df3762362c9e47e1b46f7419fd15b47d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rook-ceph@sha256:7e0bc63c49711a650bff73f4e6b5b48fd9e9eaeb01d99b2d40ec91093efe7f4c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rook-ceph@sha256:1e6fca6ed6bdde147a1185431c00cf2368576e23837b8c8511785d3493645d3a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rook-ceph@sha256:de6653d13fa4f11e148dbd9739ca03853c570559e630751518e89191f8dc052a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rook-ceph@sha256:88d9ce131d4e6cf427b2ad148d7aabbbfd0c951b19538ce17813f135abdeafea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rook-ceph@sha256:1bfba9d94edfa52e01d8e86abff970a7c21550d470d9500e84c9a9b8d8edf88b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rook-ceph@sha256:64801ec3258014a29489264bd0e6c8b1ec3b843332c300ab5fb09e7b81d43ee1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rook-ceph@sha256:c3389a2f9aa92c1d4d2da635d31f5c37b4284f8966f385ade8c7b67e9a1632a8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rook-ceph@sha256:e374975cc1ffff025fcfe49a93404fbb213d2a7edca3ad8acdcc15bcdb3f82fe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rook-ceph@sha256:12a9a634e0c9a0e32b18a8d8417064f49840e499f05bfe65f8ef28ce7b569467
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rook-ceph@sha256:a35ca244bb1e1c43b72c82c2e307ada18d9389779d35f7f46bfa4e11a8dc7f78
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rook-ceph@sha256:3f9d29538f6a46090db633f3292d44782c0de2a3779cb6bb085885421246afcc