Rook Ceph

dhi.io/rook-ceph

Rook Ceph 1.18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.11-debian-fips-dev, 1.18.11-debian13-fips-dev, 1.18.11-fips-dev

Index digest:

sha256:b862345b55390826c466b56169042cde8ccb94c2e345f3a26402e0b0453e3504

Manifest digest:

sha256:0169ac0fcc49f3ce4a3c9543ccc4526ab3196c85a8d7dac5af2c204c5b6c5c7e

Size

285.37 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rook-ceph:1.18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rook-ceph:1.18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rook-ceph@sha256:292c90808a0077152942d2d7789e55668dd4f93564b63de8f38b2daf8466105d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rook-ceph@sha256:9f4d0d612885b304d7af7443c400ad306b87bed10fef2256ee31b195389de424
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rook-ceph@sha256:67de8e31dd040ea0210c3842b3f58989d59c706c01b06807a7dddcaf60b88e29
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rook-ceph@sha256:f7ea14b0002426cd87a9f79b5207906046363a505eb296a04e8fc6aeda999934
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rook-ceph@sha256:a4ed00e41e6409e4812712b4e9c03bd56c85cc463105b048a2ffcd2b8df78c76
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rook-ceph@sha256:fdac5b0a3890ebd7889d550ffeba0ad2c9fa572097d80519b921accc91978436
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rook-ceph@sha256:9b5505cbdc89fe51be18551a4dfde1acdf2fb361f24f4017fe01176a65fff5a7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rook-ceph@sha256:25a0cc1d02928ecb584e5054a9ec45dbff869175c4d9b41826c2126df0064b55
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rook-ceph@sha256:9de1f9e4799c2b8152d7b890fed91948e43c10a01299cf611c9b3b7640b2cbf1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rook-ceph@sha256:d9ede219eec07248c21bdc073434573179e62bca06e2a57c346d0704c6f93773
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rook-ceph@sha256:74479b9f8f4ceb38e5542298a69b1befceb94e21f46dd3fa0d788dfb0671b463
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rook-ceph@sha256:dd2b7accd15423eac0d06e5ea12e7340775d25ec26b53fdbc6dd34426bd3ce20
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rook-ceph@sha256:d4e59947b503ee080dd17630a7c06e8ba4b9583a26fe2b69c380e82efce29e28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rook-ceph@sha256:6070ed3d40a0c34c73a909bbb20381a315e2dfa8dacbff8a64652e01353100b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rook-ceph@sha256:896591f91fc87b74050c774ed2e91429b2bbe6568e9f1d6792b2c5c0c2fefd68
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rook-ceph@sha256:6d9167227e1f9d89d39eb88ede19aa2b8f95f068824f172368056917c5d1484f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rook-ceph@sha256:f7888115a8d12393ecdaf8505274b0f613d2866a9c71eb6d655bfeefcdf72ed0