Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.36.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.36-debian-dev, 1.36-debian13-dev, 1.36-dev, 1.36.16-debian-dev, 1.36.16-debian13-dev, 1.36.16-dev

Index digest:

sha256:40fc2c14e0c4c84a9c1f43a47d9217a814245350245328eaa8f3883e2a69b282

Manifest digest:

sha256:0d65eb375503c2bba76a9464e5409d4654bb6986cf80479351404fabf9459fcb

Size

52.39 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:2b90787eb804eb338fc94360dbbf54ac602a1c1767adfa8bf4c41d3b4bb0242d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:12c2bc05e980c5f9ed82ffed6d328edf5f84aae83bd574819d007fd65007f028
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:39e6c0eaf502459cdff8f6eda6c1965dc04c44aae0668983bb315d28cf280937
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:13be54f5ba6aec79c3557c8dbc075aaf9a87fee78f8658025b9479a6f79c5bae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:22a9488802389aa346601e725434d31775ffd08fdd148d6666c324c2605a7caa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:44e057f966166b46006ad8f6811684d25ff6e4c65b4eda57521bc3693c804075
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:31c03d52194f98f74cb6929204a7ecdb9785067a734bcdc689bafd1126062b7c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:6d35183b6578986281f3972695b5404c0e53bc04f607c9e8a5647c347707eba9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:9dafefcf0a1d17e7a14f986d4e143993022824303bab00d4b2e6a4249cc3ae0d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:f00e79a5b9b6c20c667f5f51a8bfdcd2d267267c4abdf02c509a40fbba7c0c98
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:5de15a2ff4555972056dc700e5e97475fbef9d71fd29624c0f959a1013837e81
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:131bcf1d90bb27927f9f977f214d997c8f66c964a3cfaf07b3f23020fa130ef9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:c4c6ed43ae8199d015f4ba6671f760c305abaa361928415ae6322154fbf610d1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:aa5eb7a76edc0dbefe67bb97b4e502ab7d185523aa8c0a3f21c3ce43e255aecf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:d3bb915ee5162cfe8981682b286059caf28b035f5fdf20982864199b91f7135b