Rook Ceph

dhi.io/rook-ceph

Rook Ceph 1.18.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.18-debian-fips, 1.18-debian13-fips, 1.18-fips, 1.18.11-debian-fips, 1.18.11-debian13-fips, 1.18.11-fips

Index digest:

sha256:e62d84c7773a33f74337d29849d8cf727fa7b75c2389b6b6cc01f490e07a3b9c

Manifest digest:

sha256:719bb7af70b499c8d90d4a4fe84cef2f89005aff448f50f77c1d9dd490a478a0

Size

251.00 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/rook-ceph:1.18-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/rook-ceph:1.18-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/rook-ceph@sha256:f56fcfc0c831573ecbee7614761b12de2602d95929d96ef4c66b2e8664aad0fb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/rook-ceph@sha256:8731cd09d49cc0c5019ea58fa767151f46de8e1cf2aaeb31c46b7ca8eb49cf16
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/rook-ceph@sha256:f2b8cacdd8860be5fc9f91197c23328ccf623281885a6f29ccf70dca8dad6875
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/rook-ceph@sha256:cbfbb5653201a03f1ce88a8d3feda2bf1c3b6d13de3218ec28717b5dd8c0f099
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/rook-ceph@sha256:e63605a901f410f50da53665026772532752374a7f5c91419261c10a7f02ed8f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/rook-ceph@sha256:9e82b6ddf2d4d02248b6f0b90faffc1a68101a122e93c24e25017aec9a5f63ef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/rook-ceph@sha256:399ee9f1a963bd96213347850eb2ac10fb175b04629801524b2ad2ecc35d6098
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/rook-ceph@sha256:6486c72df3a84d6efb8d627aa62379d6556dd5d5164451de53e4118a0e97ff58
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/rook-ceph@sha256:7c67ed023c13e53f32f49b98f8275bc5c662f6175d20b738b59137f83eb0de3d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/rook-ceph@sha256:c05df943559893e912af76bcee319e4d17e5997e58e8338fef036a5663b84671
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/rook-ceph@sha256:46b3d1c697a53cf2f11fe31434c4a15b018394db4c8377baee952dca515a6395
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/rook-ceph@sha256:1055ad64a0b0e2435a2ce2b6fd0662877d768e5bc044ccf0f94985a0d9b9f83a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/rook-ceph@sha256:1916a336f1b00c4569ddb3c26d294546a85d621964f272f732b6a32248adfaaf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/rook-ceph@sha256:041b09bedf24940fae8e2c723a95717d044fea890fb2c748bbd1f568666f657a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/rook-ceph@sha256:2fffc366f42a6a0f37f3f557dcfaf6b765dce333342ebae27b5cbe08f52b774a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/rook-ceph@sha256:fd90a62467d9c111da6d8cd034addc2ef0e4d48696da09ec62640554368ad610
SPDX SBOMhttps://spdx.dev/Documentdhi.io/rook-ceph@sha256:36fe4811e548fd8396044b452734d79150c6c18eb9e9b737bb0b14254c0fe89d