dhi.io/rook-ceph
1.19-debian-fips, 1.19-debian13-fips, 1.19-fips, 1.19.10-debian-fips, 1.19.10-debian13-fips, 1.19.10-fips
sha256:d7fb557bb7296e4972d196112024e0f0beda57210f6f6ed31bc7657e79eadfcc
Manifest digest:sha256:acc61276ec3d84a29c40356a3bf79a0eadba59aac7c5086fb8b66a2c21932a28
Size
263.08 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/rook-ceph:1.19-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/rook-ceph:1.19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/rook-ceph@sha256:863ec455d42889a3d0fc91a95ef5c6a3a1d046a43b4d34d012cf738ae1563f1b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/rook-ceph@sha256:50d644101078b59cb6c01bd4c3092c51118ce92dcf813009aded25b314af42a8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/rook-ceph@sha256:a8915b36ccab4f4d6d9eb4900d2ad401f8afcb2190e0d486ec50563ebc7c68a9 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/rook-ceph@sha256:5dcaec36e3feb7a95db7fb086dc3ae0911f6cb38794b3dabfae35663eb83e45b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/rook-ceph@sha256:aafe4f8af4cd0811915b397cdacd113238c7b0ee737f3adbc8363e89e7327a05 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/rook-ceph@sha256:b9f5a531cf3486b236b938d276034862843be9e3f97b1e84fb245f664b645747 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/rook-ceph@sha256:baf34f0195eddf50340f0560f1899cd83376274d7f11831aaeb06d1cf50ea1f0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/rook-ceph@sha256:8c301ef8bf88356161ca0cd67cac54d725c0cbd17eb66befc09e12566ff00946 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/rook-ceph@sha256:8690ef2a5954aa45b75070048c81fbf6fb6b911e605e8d222d4d42d1350ede1b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/rook-ceph@sha256:32eb4bbf1fc60e1ac8d4d297a91eba46278a56831f39a70dcd3aecc3941a2031 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/rook-ceph@sha256:b1ae699c0075d33d23ef698c8b70b33849a90a01ffc3e7b0b507d3e56bb6f69c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/rook-ceph@sha256:ae7c020b770da5fecec67978a223cfc7060f3089c35f5ad5bace089cb022dcc7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/rook-ceph@sha256:90b83b8d514e8440b52120abce96b37485f3eb72db535312ada74f5428d3dc7f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/rook-ceph@sha256:bef50895baf9e83ddbb87591de098f8e3ae89807ce9f9e58af8007608db4e438 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/rook-ceph@sha256:05e961c3be82cb53d64367a81b60c4e77e41ff3a0aa7066997ddcff5af5c1647 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/rook-ceph@sha256:1c6dabe4835691df6e98e36a0afeba5a3645690cd51c26990a0e648cea874eeb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/rook-ceph@sha256:9db52bd408aa86615fd2c9e33d63ac043c48fab6be9074e12ddac301415f67eb |