Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.43-debian-fips, 1.43-debian13-fips, 1.43-fips, 1.43.1-debian-fips, 1.43.1-debian13-fips, 1.43.1-fips

Index digest:

sha256:0a7126c30a62ca78709a89c9970dbae33e06c992a216741f8bfa1bd1a26c74b0

Manifest digest:

sha256:c4cfffb6d4e8da88a6f4ceb83765f56b7f07f614115697ff0f7edbd14ea42702

Size

29.10 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:cb88594e50dbca70d255be38850b63d5b715bd24b9de962a595247726ec96ed0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:d0af4a9b25cedc09d9d5c6c528251e4de04e73afe55db95dec764ad26e856d4e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:f3626d90aa01376ab5e9ad524544cbfc396edc766b5eada2a597b610a609772b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:200f58ce7aa6004c48e39ae8131c16bc9cabc07a532cd14b83806501804361f8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:11d32ee0e97ccb253b1beffa46937abf3a28a734ad3885cdaa45462a7e48d47c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:1de0673a0c25bd9e3e0097b8b48d2e1adcf92a7b57d5f23a5ac4d89d70adb19d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:0f09784d69b58ae629363b2d46789c885223bd5ee35251625888f44ad77bc19e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:34d4786cca2da2e6b1cec499beed53aaad69c71a604b6285719c81a9d00694b5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:aa7d63235956b91b3f9147c48bf9495a26831668dda82ed7d8ea64d0b4b612d4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:e378554a3e559df032dc910eae551bbdf252a80341c6e729b3afba8df00bb154
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:3fcf1ea1598b80f6db8a49221556c02463cd6612fb16d488f7353a7868f5e072
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:376b272be670e1d2d6e3444c605274f445cfe937b6768d966242c842b4ca4031
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:b73dd4e7ca6d1dcba763bf895d7b888ffd72fc48067151ad3847f55efe9f08dc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:a6cef5225c2702630a359b3efbd469b7d1ca6f4fbc7d537f5cdf84e6027b682c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:ac011a36155912445e1f26fcd960be398b554b18ff99760492ea11f831b0494d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:5c47b787933b2daeb8be940748cdc389933922f8204525d1fe7de3f8c541529d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:b71f5aba6b3d6807dc711aaf29a1a2057ce9a575513b764ee37ce2ae437c25cb