dhi.io/tigera-operator
1.36-debian-fips-dev, 1.36-debian13-fips-dev, 1.36-fips-dev, 1.36.16-debian-fips-dev, 1.36.16-debian13-fips-dev, 1.36.16-fips-dev
sha256:36af4871ddc4de97aff65e953a6bd7c0aa14d92148c2af107804c90ac5c45b7f
Manifest digest:sha256:5dea901b10870d4d7aa9eadbb250397e3197cb96e571df7698dba8650bb60af0
Size
53.16 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1.36-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1.36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:b3abbe908735c49857091520bbbbe10d6e09ab7c532aa5f08c82a6bab0f3835b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:83ae8b95d11accb98aee910e6dd48599d9ffa0b6f4397512ad5a2f9ff8cb0d43 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tigera-operator@sha256:2802c70e8dde795eb48fed6bf2a9caabccb09836b6e248420b2e7423bca119d6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:c4d09d1f01a0eb4f61a6773624ec0244c8a28ba223687e31797be3db824e0c85 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tigera-operator@sha256:3f8695bf30e9bd700db8cd05610f38e83a3609d792988c3f81eb80f665bfb3aa |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:b36186bdc5bc1d667989ca440e0021cfb673b72cce6136bfc25fc5f7bbb0533b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:ee1a312b737f7728083eff95a8ad37dd238c67a55468bf25ff507a9c01b67b45 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:ee20f1d0b2d80b2da66727be5692d4b7a1f7639227a03e4fcc62621b6c2f3de3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:95b175fca1ae75cced6715b80e816df031fb46cb8b55f20aba6d61087b0eb854 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:865d7f91efdcb0fe6aea14561f096794416eac5a0fb8bd2c2c503e76d80ede6f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:00f8c7b5d4e067a55b92a19c4ddea60148b0e43c599dda33e8f19145430798f9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:b0f3598661376fa616e8b5adcf9b10135e122e3983968687bdc30fe22c8d54cb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:65db49dc91acd441d0d2db8160fae155569acbcc3dd3fe2ed61ad2224072c4e6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:6ec0ea40ee9cfab50457bd43490c930700a8dd4fecfb5dd8bc0d91c8989f2917 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:5e6d37df915d3c419c09e4938e9476c644ad4a3c28f0c4c9f0e7eb117fcb3314 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:6944c5999369325dfdc18fc7e50922253b3af3b7f7571a1b175767742fac16f8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:e081229e45bf716d14496ebc2f26e8064b39ccaf3eeec55f66725158cbfc0325 |