Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.40.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.40-debian-fips, 1.40-debian13-fips, 1.40-fips, 1.40.15-debian-fips, 1.40.15-debian13-fips, 1.40.15-fips

Index digest:

sha256:af5a4f6ea855dbeda8e19fa37a6207a6b0cd523c82f595295c798c968b02b28a

Manifest digest:

sha256:e37ced7432c1a4f68579a0fa94abdda43a8a50b74004fdca3467540a66451c9d

Size

28.40 MB

Last pushed

5 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.40-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.40-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:912f68fbe1e6a61293ce3a14e99f41a4a3665c70b66bf848940929925609a980
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:7864f49e258c14f357569abc41d2ddb1c40517cfd413c6b91cab2556bab78b57
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:c641dbad23684d087e4c75b313a42db5d71a2d90bd15b4a6b8834066f182e802
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:ef97018fdfae64deb11db6f791fe58f76aad39dc0b901c50b6f638bfcb2e7c60
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:376d27e23b30f31b5c5a051683397763759f27b2fd308887eb12a91c472e38e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:cd0ecf67ad0b829bded092896182074dc8179641b04fe9fb83440a2434cdca43
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:871adb503b643b1342c43fbf00291bd6f426ed3f43285b6edaf53aaea8101fd1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:71477fec788f80815fcceade11976ba642451a608f468fa111a735d142902e48
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:71ceea5b104773d433e6958cdecfdae5843ca7e7d020c0d20dd0839f44a4a38a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:62b65ebc58f671d68f1de975ce4110ec8dc0cd05dd4883cb6e240ecad8406f73
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:7e301ea4e756a27cef18bb0790037be11fb7bf5c5c6c8a5d36bb6eb97c05cc4a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:8b023f2669958e2015822e2c2b9072f9c2025043f4c46b95030361463f426a5e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:250b66adcf9cbdbd3df055f6dbb7e7d054e0ca4ca3a790b50ff01aa32a48fc63
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:ddfeeeeba90b08834c0f3d6cfcf132b00c0c628d75c6b09ebf93561f3dd6e4e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:aa867f62a17c4467225f8f32d532f23dea43652167c2a3d2e8cd8fa19a5f1938
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:eb1b3b1ee1d42375ca2cb684df1b01b3a3229a6f13cbe1261bd63bc1d25c25c4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:fac3690d7eac37c368df53790ec1837a0e5d9db1fc1ca5cc3d12628b57635fc5