Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.43-debian-dev, 1.43-debian13-dev, 1.43-dev, 1.43.1-debian-dev, 1.43.1-debian13-dev, 1.43.1-dev

Index digest:

sha256:5566702093bfd08ae80eed453fe7e8dc3013c62f93e5c622f68d3b99240d6c53

Manifest digest:

sha256:2e3bd8cd60e86f7bb274b87272a4c2de665a15592c059598b42fc95934d76d41

Size

62.66 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.43-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.43-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:876619d574d63e19fa88c0356ac550fc1773b5c3ab5b03a4ce1ee2f459c96218
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:ac9b9712a72415c255c9bac4f1f2c146f18db83cae8d30bc51fb8f2c3414cd50
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:4c8fd15a325a9990431a55e34cb2e82245d559fc7827a6a7bb20cd319be99ea9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:552c265f0b556e8eee4b753a58f758cf97b0bf3e16638a3ccb89b3a85fc79eae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:2f9eef78ef22211dfab0fea8d37ef0d90150d8b087fd627c2c759d5c29ba77b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:f3191d55a6ae7e842ea738a6359fd62c37a8201e40c09d5933ebae091a92af2e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:2e9e9e8cfaff4616bf01561da7fcf293401c05fe6df259a4220b7d3322becc65
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:93e606ecd53693328b9fbd6ecc7c90ebb39e03f7aa786be27faf78fb1be3d748
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:8fdd7f2635f168a66f6e4d5be06207c29fe21ef4f8fc0e5f419a7b5521b67fd3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:17c7f85e97ee4717dffa868fe06172d6a8c4010f29caaca818b0cf9342115224
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:ccde3fe84cb7f53eeac155bda676b8e5901f13fbe796c74ba131415c658e9d7f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:3e544f9940d920fb6a70d72b2107d4fcebef39a1da24177fef6a90bd23efe3d5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:dc3a4f6d4d833e6f18df2b8c0adc0e099e732fecb1ea548abd3b703be7ca22ea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:28e7d49cf6cd1ec31bba027613e4b505862648ffe990c7627962771cab589ebb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:f5e4b6225dbebfb102711021affabbe3d7892d11884bae0d6e503ab53511547d