Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.41.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.41-debian-fips-dev, 1.41-debian13-fips-dev, 1.41-fips-dev, 1.41.1-debian-fips-dev, 1.41.1-debian13-fips-dev, 1.41.1-fips-dev

Index digest:

sha256:291a74e6d635b911a6d29ced93ea9cede0d712b64a8fa3be001f2a4c572345ad

Manifest digest:

sha256:815f2b2fb747e86621b5d2994f37fa3f1b5a4f7a6694548a571ef0ed0ffb2d32

Size

61.77 MB

Last pushed

5 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.41-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.41-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:28139d3f0233edc9760f3a546758894f9e183372d0260781cc75b15bbf997d6c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:097454f6c0042845e200702d1bcc65960a31e5a4f5c76ca25b99750c648468b8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:87cf7ec5ab574b8a9f47b61526143053930c53425de19ab1b4ab968e71ecd2bc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:1bf57a713fe0d9fd09293d9ed88a10ef25b89219564330ea682c8aa80816540d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:67b86564afd08e7f7aef670c91ed74c7ef92c2311f49f2b2f2dff1c826fd6891
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:790038d34f7af1f7c1072e513b32b90b998c6f31babe837c664233a6430d5b44
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:2de2b4c71b13d732eec20344b244124499558dad6b49cab0a4a831bd27c4e8ad
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:3fe74d8404220c8f4a5c91ac6853d96e837ceb08659cff28666c829261942fdd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:baa85c6dbeaaf707c7375c1b249244d178a77cf4f58c8f48dd28f16023e079ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:6e29003771d8a081c2c637e05a40c36682d50ada71ed966ab93ff34281e22fe3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:2b42390f9f1e6b9bea9f9b1f396432b8574e23ed49d2880a9b88539f79cd3ea3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:13e8b38f382f4d62e24df8d8538aa5be00add498c1c15e77362823802cf2f3d6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:ae944a6a957f4ef077749c651e64f178c80adcacd28f7a901f2b91bb18222b6c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:cc79763990a2ae4ad42361784b236d0f8118f67e1baa1ea03cbfc938e6a02e2c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:31344500b49099a8996fa51bb4ea33548ad42dedd24764f6334bbdbe2709efa0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:89e769745ef8ca789ba4520ef87f3555e465ec5203dd94e7fbd77a42f7dd8cf6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:0951f6b1718fbc51aaef1a2a2fd8af8d577896e7d028f3fce15ba67a0f473018