Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.40.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.40-debian-fips, 1.40-debian13-fips, 1.40-fips, 1.40.15-debian-fips, 1.40.15-debian13-fips, 1.40.15-fips

Index digest:

sha256:389ffe21139f6b656b6e8c250f24f62af6b53d49a60418b9d594dc4c4d8c230c

Manifest digest:

sha256:73d68be1410a01e5cdd13582e78fad39be0e903b1e5bb90bce9acc5d7afb2345

Size

28.41 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.40-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.40-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:bbfb05addfc359c34a791dc3b7aa00fc96c097dd4ec7aba9a8235d07e555de5a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:090a2cf4ee3ca5f3e809b065ca10bff1403128b4301b62ce8bab05a1e168de68
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:7b447d1547d8cf6baa583076869d9ba34483b5e6a5472b5d929d63ce5b5906c4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:7c1e66cb6337846e726edb9a1086e9d76d8bd36a2284935a53500ecc1c4f7f43
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:19673aa690bccd9e8665df30a9db8cf4757d699bca18cedc9ccc1292cae68b88
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:94b69dd7b9b6badbb75b5b07325eb5c91beac8082998f8ae33c526fc110cb4d8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:4dc23e5fe3535be052b18ca64495745ea4afb57bffa813a80956fe9c2ca195bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:19228a55c8de2dd7363046d71684aa47e89ece85508abc7436715d2374b11e62
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:a466b8cd1b7374008ae2f94b45763654a030fd2a68e523712231d03c55418f23
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:f0bb3471448aad586a9380d7052782338ea9a39f3138a1ff4ee6dea7e0c9b351
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:1bd27409b7fe37cc05f71157fde7011b82cad156fcec10d043c61655ed76dc7e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:5a4c7bb1386393ddb9bc197ea85009dcc2fb53d47181b2135d88dadd1c0133cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:38aad09d5e0fedc044a6b9a1a280fb3b07de1287ac4801d87f60c02e9755da5f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:797c6b7b3619b05629b4b498ae51859676126ea05c9426a13433781db86e9407
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:7de615e68c98e8e4747c770388ae3ebbfdd89e20674062a62d952aa2b015e48a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:882e04ac8dd72a2b895e1c19ff43b27af57f0c2de9f0543ff75c6021debb2774
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:ae045416da9053226ea6ad777c322c28f623e6011b905fe7c62c570f791dad3d