Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (dev)

CIS
linux/arm64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.43-debian-dev, 1.43-debian13-dev, 1.43-dev, 1.43.1-debian-dev, 1.43.1-debian13-dev, 1.43.1-dev

Index digest:

sha256:8ee2ca72d91e662f7d4978459b20cbe89f8c111f88ed06a2d504448464f9598d

Manifest digest:

sha256:6a42b4102f2bfa795c5f7f7f4663498732d42b4afd512509aa85c638456048f4

Size

61.40 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:fd3e0295eb04b0a716f27ed441c30fd1cbca409a4d10722eeb4daa62ed5bdcc3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:6680469d1bbee5fafb2cb9b05b7b7ef35559eb8ba2552e84a2713799e2af4203
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:a7b81d43c080aabc04b4d5c07e71578bf1e2f72eb67ef2d9a8c1af437f2249d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:55a891939b41b45f26c66868531029aca7ea4837067ba3ac27b1b73ef5a0cdb9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:50b7663649a5883da8c55a510786028f52c12f321483cb1c37ceb5948cc44496
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:5fbe424541142660dd3076c3855bc43f355beee9ed48fe52ef2074da2fb341fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:3fd9c598c6a16b99d8bcf021b9daaf7a32b14fd0c3b9691f07de76978ab1500c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:ce03d940be148cfe4ffa4129c4ae181b475d009c96f812378e8e45c84c0d5705
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:331eb9858202cc597e0b97a1fe08b3c38a7a72d3cbfdda0fdbc7561263f0e723
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:39ce56545e8d101723c9cd975633e140ac64cd42db242e1fc254f014c3002fcd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:033ef99a86d4015d1f00afca53fcea098260bbf3e34a6f2f15c73656e84bad4f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:e466a7881334ba714ded9f823322c0185569c6b4899f2a52b62a43cb26065a25
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:bc02f6504dacf68cc45591129bf0afbf8ce7d9a8a64f9ae199ff614b9d9a86a9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:b340335c9b4380a78b16de81a11b520ba19ecaa19b0846d3d2ef23f2354d7e1c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:91ed01a3e522d7bead65507ac0a23e19695960d734f9e4c05e79d42e88f05b5e