dhi.io/tigera-operator
1.40-debian-dev, 1.40-debian13-dev, 1.40-dev, 1.40.15-debian-dev, 1.40.15-debian13-dev, 1.40.15-dev
sha256:8c4d1df3f0c6de3d6a32bfaf1ec585e5eefa6ed8c8fe54d2a803b815ede87b1d
Manifest digest:sha256:d20ac982431908e2238a86abae47902abab257601eb96edd838ccca96c4c10ed
Size
61.30 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1.40-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1.40-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:89ee5473b90e964f9055d5037bf28e3b98d0b40a1626eae6566821a812663f3b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:f3716d6412cc1a3bf53b44fd2f8e0113abf7fcc48b296267b3a43ee2a0cccc80 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:cadb4ba24125c5b18f770d29e5a38c2715ea5253a5225ae681ddab071d4d03c3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:bc4ed644d6bd02b36a8997f039805bf102143c67c60d0a559152d12c9ca2573f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:667ac05660abd85ddc55fe7a737da9475edb1e5795043e160269c611015a239a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:61871a2403a02018882265d5efaeb59020790f376c7e7d5a7bcca20a4b6887c4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:4d1b98351563640f15573ec36acd1c8da39fd57839f39434168c1ae1aacb4444 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:01b39ff2ed07628f3010a6384d2bc3dd25e69ea9222048c374d474b2231f7f8e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:e768cff1b4e545e4d1938bc51a1f7704a6d917840c8920185bed2a7380d25761 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:eef0e293567eecfa360e585b7a0a8bfeb0e8c093bc7efcad4babb79fccd22eeb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:67ad3ddad4b6ef68025a6c02c18a3da3b2fb0a0f5cbb6e21ef43f7ac870b990c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:7a91a4a24fa3f1daf7d8e3ee8daa4757df8e3ef0e687ea6f9d3ab8d0ccd69ad4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:d7a6971ac1f5461ffa60170c1df182871d8fc7265d4bb823e557ffef4d50985c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:4ecc0336b1a8dd5ede61fba435ec344c61aee469a82926194c98315b22a378c2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:a0328788080a82e6511d5fd34053483896802c874311370e32c88a97c0a0600b |