Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.38.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.38-debian-fips-dev, 1.38-debian13-fips-dev, 1.38-fips-dev, 1.38.16-debian-fips-dev, 1.38.16-debian13-fips-dev, 1.38.16-fips-dev

Index digest:

sha256:49f2ec4ce225fd7efae56644b8e739d44af7a4d692e1d81d1cf8307e43bba748

Manifest digest:

sha256:38c58ecf364fbbbfe61cad5025cf3211c8542a37bfbb003f27be1577ffb82a89

Size

57.44 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.38-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.38-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:d00cf90693ef9c576af5386546f6b75d24a236bbdbb61fd55a0e0fd87e4ee624
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:4bb032348a4b4f8b0830e03033db269bd1fe106e138d6ca7464eb024862d8e71
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:bc6ab41fa1d70609788392664090dbeeb220feef8ee802de6b3875a617d52b70
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:eb07f3372a42ad16ba6433a6c004e5aabce764b2287eadc101b3923f8b06585c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:0bdfe8fa7ace4aeb7f5e826d04031a2c72878075fbbcacd4e53b66951de84b33
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:888f9d20c3a505e3a67a6bdda35cf23295435cd6e30d189cc2aed590b1e1cb2c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:832a552889ce97a394dabd8deaf099ef4a270be4f781cb1a55e21783bf69c4d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:08d0ce5d81f479ede628ea403bf198b9ddb2db414ef9b092e4adc59ab075bb0b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:231a0e15dff6e6497c21eed875111bd689448875481a39e25c86d921313f07fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:2f2db7becf4c979ac81e831bc4ce709bc533576762926f6edd4ccf18024be839
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:d9fc9c265454d53dc02e4ab481680183a7ed35e668f1d39d7d0a2f6d9a0e5fcf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:8653afd1d9eb15ec9e900910bc86b2ecaf17ee5eaa891af53d42158d1eb2e7a5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:ec87db3d405212e11e3f53e332ebc0f8ed9d8022d0b91d53cda19c7e916c78e2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:12e639eb52673eeb122f2ec67bb1b8724cfbc840822d7e878934741070b2e4ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:5b8db1908729796e19146aecbc680417d33751633872debd47b928d37b80cd31
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:d66b34514b16b55cd5c7b845bf74fdd23cf9f6b6be84ec2f7c1b577c375a9c62
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:920ff1c8b44a8dc0ae6b0627cf387ea53415ebd564ff67ae73e1112c14ba7f16