dhi.io/tigera-operator
1.41-debian-dev, 1.41-debian13-dev, 1.41-dev, 1.41.1-debian-dev, 1.41.1-debian13-dev, 1.41.1-dev
sha256:359c9af4bc200da13f17e3cb36fa9b07c1f46a225afc0f317d4805c5b127ee30
Manifest digest:sha256:3a3a179c04260d8ade81878882658d4bfb3e82de8cb638a58089def00d41f57b
Size
60.96 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1.41-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1.41-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:01b7f5ea99084b85ddc883a58cd5f3440375e8f4df378ab33cc478bb1a003400 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:d2bc7e62ebd8f66fbbd6af987876fbfbbc1707f037feef4c459879a6052fae84 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:3a60f434531a14366aca182365cfef4460d2fad4b061514deaf2acbc869a5184 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:a3213ac32860f6bea36cadae819d8012f703b6d0d0f059740d7437b36932ed97 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:c26c9e4ff6e36013a83450dfc1ecad1fd0ec0053a8cd8319c92efa9dfb1764c7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:0d72d63f5aedbf02dc2c3ca69fb63317ca0fdc926769496c08e18017bc836cbb |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:24e03653abc03a985d487a69a7aa0db729be4e6ce2516f74f9f2529ae523aeda |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:505d0a51c1a2a1ed0c191812e58a557a62eb2d3ab5c78a1eabe9449bbbc98752 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:4125a1df007564d211d510c1a5fd4be4a7cbb3d3f031545f6b399c61af29e270 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:14a839d94916350bb36947d56a1711f6563f22ce6ba00425f11bed173b494e33 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:10c29b1f076b9cc72f3f80161437b5766dcf0a0bff653f9d230fd5f89a3f6223 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:0e3df9e20e3248091afd5025b626fc2930153b3dc78d12ca4b04393e9ceeba16 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:f47483b556924f6f4be765a17995d09623fb9987f3d8a9b61f10d551d414dc41 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:7ec711c15478eea89890d614015ba16c54aaecd774d62a8b9f41b5ac592af55a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:0cc012d8abac3738c8c8992e4ea474f5dc7b964757611093bc45293642f110a3 |