Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.40.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.40-debian-dev, 1.40-debian13-dev, 1.40-dev, 1.40.15-debian-dev, 1.40.15-debian13-dev, 1.40.15-dev

Index digest:

sha256:8c4d1df3f0c6de3d6a32bfaf1ec585e5eefa6ed8c8fe54d2a803b815ede87b1d

Manifest digest:

sha256:d20ac982431908e2238a86abae47902abab257601eb96edd838ccca96c4c10ed

Size

61.30 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.40-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.40-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:89ee5473b90e964f9055d5037bf28e3b98d0b40a1626eae6566821a812663f3b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:f3716d6412cc1a3bf53b44fd2f8e0113abf7fcc48b296267b3a43ee2a0cccc80
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:cadb4ba24125c5b18f770d29e5a38c2715ea5253a5225ae681ddab071d4d03c3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:bc4ed644d6bd02b36a8997f039805bf102143c67c60d0a559152d12c9ca2573f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:667ac05660abd85ddc55fe7a737da9475edb1e5795043e160269c611015a239a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:61871a2403a02018882265d5efaeb59020790f376c7e7d5a7bcca20a4b6887c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:4d1b98351563640f15573ec36acd1c8da39fd57839f39434168c1ae1aacb4444
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:01b39ff2ed07628f3010a6384d2bc3dd25e69ea9222048c374d474b2231f7f8e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:e768cff1b4e545e4d1938bc51a1f7704a6d917840c8920185bed2a7380d25761
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:eef0e293567eecfa360e585b7a0a8bfeb0e8c093bc7efcad4babb79fccd22eeb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:67ad3ddad4b6ef68025a6c02c18a3da3b2fb0a0f5cbb6e21ef43f7ac870b990c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:7a91a4a24fa3f1daf7d8e3ee8daa4757df8e3ef0e687ea6f9d3ab8d0ccd69ad4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:d7a6971ac1f5461ffa60170c1df182871d8fc7265d4bb823e557ffef4d50985c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:4ecc0336b1a8dd5ede61fba435ec344c61aee469a82926194c98315b22a378c2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:a0328788080a82e6511d5fd34053483896802c874311370e32c88a97c0a0600b