Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.43-debian-fips-dev, 1.43-debian13-fips-dev, 1.43-fips-dev, 1.43.1-debian-fips-dev, 1.43.1-debian13-fips-dev, 1.43.1-fips-dev

Index digest:

sha256:61e4b3ec7de299ec121a94a899b70683af9ac64320067cb572aa01a2900fddd8

Manifest digest:

sha256:30814d70ea95a3baedb1f0cb926302e1ff9f21fa61416e09b24c2aa8f334af23

Size

63.41 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:a8c118c1f44183f6bffbd3b4cec222bd0a9dbe4555b5a597e488ec67c4222d35
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:38187b1bf15e7c0190aa82dd3b6f989d769ad4d5537022f2222e637bf7277338
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:5e5468914123f1d47464b5749f97a086701f0de4b95130698f46789c2c1a410e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:9d9af19e0b598f8063080f74b9021d76e0e9fff20e96a143504f27df377c6a76
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:2aa11ad8495214ad70be4a58b07041c139d4c02e9962ecc03d233100f76341ca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:67217adb1c8eb1edc8441c40fd42bc61254a0d815053e7b15fc2d0ab7c591f1d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:ae7a0cf6a5c29acd8a075d4c5eaeac7d7d6f04eb9a1672db890bfeeb29e5936d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:651b2f7e545067b41b603bf7ac1e3482047ffd41c594894dcdd65fc413f9da88
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:3067db500f1398d7e0f4d2848f50647d8f8ad231b30991523d293b605c3d672f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:ebe26b320c57e6b47e048f17a5774adefb982297097e904d4589218acb94d1b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:d2c14d45f0bd97cfa4dd066acebebed4ec9aee2fa56eb3a14a3a2b037b44469f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:2273bd17736e964ced95de051a01e4eca8872674cba63799e9ba2be848596c44
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:f480a658c6e927eb47d5e927be36cd715351e4d7d997b232521e46d68bdd3efe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:ed935d761117c61dd9ed64876f2ece18988b9e5dfac8389ed6edbe6fd7d99696
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:d9a255e2f8becdf2764815ce01aa4f0f6d35bef5304a1ac9c047a3a96c050859
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:80e5c65ca3d0f1a05ef2d7b3c56f1ff5b652a1fa2e060c1b86e2068631bc7f89
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:610d4782f7e590f48503920cab0feeb60ffb9882a808db53b053f084260760b0