Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.41.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.41-debian-fips, 1.41-debian13-fips, 1.41-fips, 1.41.1-debian-fips, 1.41.1-debian13-fips, 1.41.1-fips

Index digest:

sha256:1201f8677f52c7c72d5ae6794d580bdcebcb7da59a3cc4a6ede0c7249d2f6180

Manifest digest:

sha256:4c639a6fe0946a3787da59b756505e948b06e9190a71dd2203fbdc83388fcfdd

Size

28.24 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.41-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.41-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:d6fe9241709f5b73620da60b6cffb5ccf324c29503a602c41e17297779f2864e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:b270c2420bf98c2cf9e615771e6bcfdfade81ddc3af9a46fe4a3d53f5ea7118e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:7a45c534f7c3abbe254b4cdd6ab9af52156e4c6517c2824de39f2910b4c2b173
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:f8b8a372901907d6535b83e41121d11c26d85393f41e8ecfc509f34c5a899132
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:5209475075b2122fafcb198272401d60c252f665b0691c4d079983f6bd84f501
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:c421d045d9c7ccc44d30cbd39e354002a62b7b745f6fcc3e2c769ece5f62cb59
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:1d945ea9b1d095d3d3e0d8b116ec95f72be70f2dbbe2c6217718b73a60b32ace
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:ddc410c62b1b1667c1b5215a2befdacab071be8c56574ce9487936943b99df80
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:8e6dd5395980c2da12275512c1891efec351eb41615ab33d0f0f7926e5719606
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:c8461c7b2558bc14ac9b8ed584d0f8d6346e684a1aedd04bf1b7ac22efa7c3f4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:49cc7bdefe11dc1a3babc770dec3b5156a65042e1485d63a8553cce3bba38f5b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:584cd7a090567dc96a67668bb9117a9e59304aee3074a45b687ef00dc888a71c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:b348be6703885347d1e2bc011d7929f0c3f54ca3b342164e1e0bdec34c14496d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:a1dcac170a5537498140f1f3b232e575a078fc2bf6f68681527a4ea4ac70ed16
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:e4e0357e688a797e5dc3bf53facfe04a3693bd7e6877c57ad1bfe5ae77118186
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:bf8fe7bbef2df34c9b6d4e3e15bb073059f0b936c1c9ae55cc76980689bbfdc1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:8b4dc311a5e6d7946164bf3f00e44d519c134307cb9046032a4e5ffd0d4385fa