dhi.io/rook-ceph
1.19-debian-fips-dev, 1.19-debian13-fips-dev, 1.19-fips-dev, 1.19.11-debian-fips-dev, 1.19.11-debian13-fips-dev, 1.19.11-fips-dev
sha256:ad15ca20f70ab5e25e2e54a104a26cb3f08dd6fabc9dc544232e5c6610baa823
Manifest digest:sha256:6cf3595ed2295a8d06acf151b22f8c061797f3178c74c5718e1b61d0b4746625
Size
300.52 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/rook-ceph:1.19-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/rook-ceph:1.19-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/rook-ceph@sha256:7d28160d838772f1237f5368f44ebe0386c2c7fd7bc805d8d6240a2a2cc3dda9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/rook-ceph@sha256:3728bd1f506be75aebf9a56b656dd139cd084437243c0d45a806ab043d7a82d5 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/rook-ceph@sha256:6024cc41ea345f540992e4b68482e0a758f7b9a5aacbcb5408387fa13833a51b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/rook-ceph@sha256:16df26bfb25a8eb25e95d431c5033a1f154f2f73f50764e9e4cac9dfa535d4c8 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/rook-ceph@sha256:697eb1a641faf0b211a9b47937cc716754e4d4c05843e8c8b5c38bb747f7f0b4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/rook-ceph@sha256:7d04a91a0d5679e8bef11933b213360bc98dde6cd302b4b8f45c005d7f06f774 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/rook-ceph@sha256:cd2fcc6cd766e39ed39be8529b46652a900f99957ce83ff81b751422889a6d24 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/rook-ceph@sha256:6d7275442a626b315496e8094bc4f1c94323c2e0c9c47cecc33a2e0b6b28d676 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/rook-ceph@sha256:ba88b8639851cb3c5361872466e54fb0ed63760f3fc803d5f8d5869978fddf49 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/rook-ceph@sha256:b5db4ffc3b300dfef570091fd341e4390ef0076f7794ebea73b83f65efc14593 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/rook-ceph@sha256:e7fb1dbdc406862bc29c6b283f68510da031554f9ca59e1389530c6c6871183f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/rook-ceph@sha256:52cfa72abddd8c80c9e3529293d2176d2c907d25fbeea64928bc495a54327a0f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/rook-ceph@sha256:c8ac97ae69ef77d6872c883571c1ba5afa659b7c33770d52eb42e42e5a24d5c5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/rook-ceph@sha256:8bcf53a9e0d4f4fe5b070acefc4bb6b22644eedde9e89785d6ab3129d806be98 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/rook-ceph@sha256:1929c2714414f10705e3e9d1d75a4e2f41c98b4aadc6e5da1684f624a6ff7688 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/rook-ceph@sha256:149438b70b500f908c5bc3e4e3d569d31a72dd511b3d1986ac7ce34b571e5270 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/rook-ceph@sha256:3e5c171de5ef14da28c962bf2c68174c3fef563a0f07e10338efa25b86839ab5 |