dhi.io/tigera-operator
1.43-debian-dev, 1.43-debian13-dev, 1.43-dev, 1.43.1-debian-dev, 1.43.1-debian13-dev, 1.43.1-dev
sha256:5566702093bfd08ae80eed453fe7e8dc3013c62f93e5c622f68d3b99240d6c53
Manifest digest:sha256:2e3bd8cd60e86f7bb274b87272a4c2de665a15592c059598b42fc95934d76d41
Size
62.66 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1.43-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1.43-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:876619d574d63e19fa88c0356ac550fc1773b5c3ab5b03a4ce1ee2f459c96218 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:ac9b9712a72415c255c9bac4f1f2c146f18db83cae8d30bc51fb8f2c3414cd50 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:4c8fd15a325a9990431a55e34cb2e82245d559fc7827a6a7bb20cd319be99ea9 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:552c265f0b556e8eee4b753a58f758cf97b0bf3e16638a3ccb89b3a85fc79eae |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:2f9eef78ef22211dfab0fea8d37ef0d90150d8b087fd627c2c759d5c29ba77b3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:f3191d55a6ae7e842ea738a6359fd62c37a8201e40c09d5933ebae091a92af2e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:2e9e9e8cfaff4616bf01561da7fcf293401c05fe6df259a4220b7d3322becc65 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:93e606ecd53693328b9fbd6ecc7c90ebb39e03f7aa786be27faf78fb1be3d748 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:8fdd7f2635f168a66f6e4d5be06207c29fe21ef4f8fc0e5f419a7b5521b67fd3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:17c7f85e97ee4717dffa868fe06172d6a8c4010f29caaca818b0cf9342115224 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:ccde3fe84cb7f53eeac155bda676b8e5901f13fbe796c74ba131415c658e9d7f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:3e544f9940d920fb6a70d72b2107d4fcebef39a1da24177fef6a90bd23efe3d5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:dc3a4f6d4d833e6f18df2b8c0adc0e099e732fecb1ea548abd3b703be7ca22ea |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:28e7d49cf6cd1ec31bba027613e4b505862648ffe990c7627962771cab589ebb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:f5e4b6225dbebfb102711021affabbe3d7892d11884bae0d6e503ab53511547d |