Sign inSign up
Ceph CSI

dhi.io/cephcsi

Ceph CSI 3.17.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.17-debian-fips, 3.17-debian13-fips, 3.17-fips, 3.17.1-debian-fips, 3.17.1-debian13-fips, 3.17.1-fips

Index digest:

sha256:ed53f738e552dc168a5202cacf331952aa4614033315217ce9da0eadeac350f4

Manifest digest:

sha256:c7d81eba04fff343d7bc7247e2e90ceb94047305004115b09d82994a11f53306

Size

125.81 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cephcsi:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cephcsi:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cephcsi@sha256:821049faef6f364b1b955a08ee3f022ef911c6d7e0d805a9fbc08f1f3647306e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cephcsi@sha256:0ca2550788d37efbf4b410e3202db390a6d1630d422ff86cb86c6a8a1a27123f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cephcsi@sha256:3365fa26ee1948135102ae66941620774e69697ad5655f7ca50495405259e027
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cephcsi@sha256:5b6b4457055565b477904e066d425b97a17d293407c99763cc78ec871906bcff
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cephcsi@sha256:00022b2750d0f09d5559633bae9e5cdd333bab4d2c1dcc9907959de1d6212249
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cephcsi@sha256:29e2cad8278a7abf7b86e7ac5745f1db2fb31a2d4213cab98c930241a44b7507
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cephcsi@sha256:b5aeb183ac21489b83e48573a1fb4c928e992f81169950f0627afcdc1849bee1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cephcsi@sha256:5bec0936ae5e49273a0f1a2fc2bc23ec205b85b4a8e99c3497e735549eefdca9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cephcsi@sha256:2ab747d710a87b8daabf68176ebb6ebb676271b0580fdae72442bab8c17da879
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cephcsi@sha256:747c5fff45df98c1dc0fed7a8eb916c4d78ffa54562f6716385aa2df9ebe909d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cephcsi@sha256:a26ce32da1de2d6de355c43ce3d37accfccceffeb9d99604c031135c10befbca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cephcsi@sha256:ba84650c72ef657bdd53dec53ad00e69822accc23dd5651b39726fd24c3e4c7f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cephcsi@sha256:44b2e7299b38500600d3cc1c938d9b8efcefd93df18ad899be340149c962f9ae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cephcsi@sha256:5ac2dbae78764647d85a3ef5726f0ea8d9e9d8983285c9cfd477f2f156fc3a11
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cephcsi@sha256:d6b84627a9b1b77c3f0a680308e9628cde55207d424429e0658ef006617adcaa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cephcsi@sha256:24cd626664a7a3670267adeaeaa801b2327b0fefe0bd56424ebc19a0febafd3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cephcsi@sha256:1360bf1546ce679bc542b673ce2876918b8e0ca9a7290092d1bced83bad92760