Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.42-debian-fips-dev, 1.42-debian13-fips-dev, 1.42-fips-dev, 1.42.6-debian-fips-dev, 1.42.6-debian13-fips-dev, 1.42.6-fips-dev

Index digest:

sha256:18e90f0ab3ccf32febdd2fecb52e635c98675bae17f7f698d2396ec58105ca87

Manifest digest:

sha256:e5778996e76606bda6afb4b8b79f1305bef0ca065be51ca2c01064685acecf81

Size

62.56 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.42-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.42-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:7a6c3a34275994ce8166247972bf9ad8c2bd1c878df529a802e7452c2bdeedf1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:1e5a956799ef7308a38c9291d75146527ca22c48fbefae6d4e23e7cd843e85fb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:e9bb4087e08771ec36e499ad6b85872e468f01c84b985461a09c237df396e7a3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:eec11c385d8ec3412473712bd01b80a423443bef8d07141a7f93086612f3dd4c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:d136b6b22e7071dbe93266ae0023b3282dbf356c7a48a8d69e9b9d111ee5b443
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:9201fbbc71e0ecf8f8e22cc57d3afbb1a7f2f8cb27b62164078ec9dfcea495c7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:be4d8dc578b1c527f8c1dbc0141f01fd052bece0198cf2316d8e65430b508856
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:3f85a5d9ba6e9128e6f3a5d26590f21032fabd651d3253628b5248a5b4b7dd5f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:1e77fda4671e692045cd41c8986cc7e3f2b8b6ea7cfa58431e3fd8e27968d50d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:18e2397bdebb0ce378d6f9727df40a683021db079da31e218aebc096ad77b98f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:db4ced3400e0b5614d096de7df6208f46affee0e6a560d140004c1a22db58680
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:72000ad70af1b6cd6dd27648b2c588dc9202b1c0bc5c8de6faa08c2d8045396f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:e2480a7be0512426ec957c36307e6a6ab200922e1afbfcdeaea2777308776477
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:eb921de7fe5c8e7963c22142832e4a463db00474b1142aa66b52e93a5eacac1d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:00209939e034a49d0943495da8d2335a11310938197a162c25da889e19a43a3c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:ddc71f180e2c5dd4a8cf7d2690a03b1424ffd0f14bbfe453146fbe122f30fc0e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:be4057cae6eb6be724bdcc761192ba603befb1aed1fd8eb8cea04ed647a00867