Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.41.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.41-debian-dev, 1.41-debian13-dev, 1.41-dev, 1.41.1-debian-dev, 1.41.1-debian13-dev, 1.41.1-dev

Index digest:

sha256:359c9af4bc200da13f17e3cb36fa9b07c1f46a225afc0f317d4805c5b127ee30

Manifest digest:

sha256:3a3a179c04260d8ade81878882658d4bfb3e82de8cb638a58089def00d41f57b

Size

60.96 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.41-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.41-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:01b7f5ea99084b85ddc883a58cd5f3440375e8f4df378ab33cc478bb1a003400
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:d2bc7e62ebd8f66fbbd6af987876fbfbbc1707f037feef4c459879a6052fae84
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:3a60f434531a14366aca182365cfef4460d2fad4b061514deaf2acbc869a5184
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:a3213ac32860f6bea36cadae819d8012f703b6d0d0f059740d7437b36932ed97
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:c26c9e4ff6e36013a83450dfc1ecad1fd0ec0053a8cd8319c92efa9dfb1764c7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:0d72d63f5aedbf02dc2c3ca69fb63317ca0fdc926769496c08e18017bc836cbb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:24e03653abc03a985d487a69a7aa0db729be4e6ce2516f74f9f2529ae523aeda
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:505d0a51c1a2a1ed0c191812e58a557a62eb2d3ab5c78a1eabe9449bbbc98752
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:4125a1df007564d211d510c1a5fd4be4a7cbb3d3f031545f6b399c61af29e270
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:14a839d94916350bb36947d56a1711f6563f22ce6ba00425f11bed173b494e33
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:10c29b1f076b9cc72f3f80161437b5766dcf0a0bff653f9d230fd5f89a3f6223
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:0e3df9e20e3248091afd5025b626fc2930153b3dc78d12ca4b04393e9ceeba16
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:f47483b556924f6f4be765a17995d09623fb9987f3d8a9b61f10d551d414dc41
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:7ec711c15478eea89890d614015ba16c54aaecd774d62a8b9f41b5ac592af55a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:0cc012d8abac3738c8c8992e4ea474f5dc7b964757611093bc45293642f110a3