Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.42.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.42-debian-fips, 1.42-debian13-fips, 1.42-fips, 1.42.6-debian-fips, 1.42.6-debian13-fips, 1.42.6-fips

Index digest:

sha256:65e0c3d8113f0c468426c97f44cd349dafb9797905600e65e431a162870a00de

Manifest digest:

sha256:79e7db34381e24bcc935d3efcc109c2cf0c2a038426e744fbfbffb402b27f8e0

Size

28.51 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.42-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.42-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:66db450fa78faff9eeedf4cfc4ee70a90f4b9bbd710ddb2bde68d462653b6984
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:be8e5b74245ec5094d2fa25dc3890bba58e2605640e3588eb811279d533de1f5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:8991e7664593abcb9473f4661713758c0a13ff38bd1140920faa553023eca01a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:1cc21682bf36507026895055b810fa76eec9390258e74ddabbbeb51c398b91c8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:f90fcbf441084b24eb2b850bd5077cd6175c59d1e30015942cf6415031967341
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:5bda803f74c5f332ca8ed75e5c3b19353c7ff50a6901befd051803b3742ccf28
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:3a35a5b7765e3e3345efaef44ba708a930f271de74569143cc598ba324472370
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:0562c619675218994be57b9efbe9af4b8881d1d42442f1295266397a3f041d3d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:33506fd6607d5a356e35395d246ab08a69ebb0d0d08b0b4eb17396f35110bb1a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:1211a76d8e761036db10919b01152b4e991ab41302cdd809760e0efa0180aeef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:2ce4fa23a493f40af15a22f471b076917943dc5565c46e318ced26c2968e39e3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:a9c6bd9f391939c235da7c19a5d7fd967743e8b990eac15ba78687a49bd3262b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:f08b98f2386e05959de940a78cf97304f7f4b39cbb76d7afd9bd95c0a8fe488f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:11bfc0ce5f0898423a83420a09581631289245f5647818a17b9097770fe5f709
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:0cc0691886b7600fef0c237264a585fabc90e0f1506d578cdc07cbeb14a57c28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:062f6482873eb4259334a1a7fb171bc9091d125cb93b6def34e7587afc720264
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:3666c102b262c8ef211fcd603a96c7e7d64050865470047634478ae749d7d862