dhi.io/tigera-operator
1.40-debian-fips, 1.40-debian13-fips, 1.40-fips, 1.40.15-debian-fips, 1.40.15-debian13-fips, 1.40.15-fips
sha256:7fab4107a9c8f767dbdf72b8969d11cc3232fe8c365f30f359c6d9948c470852
Manifest digest:sha256:ff752f3075fc75c1e44d355ec25b3b6b26b8603aca7d7f266295c3f9e2174218
Size
28.41 MB
Last pushed
21 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1.40-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1.40-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify