Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.41.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.41-debian-fips-dev, 1.41-debian13-fips-dev, 1.41-fips-dev, 1.41.1-debian-fips-dev, 1.41.1-debian13-fips-dev, 1.41.1-fips-dev

Index digest:

sha256:66af773d7929dc0cef554f43053f41dd0ee887d7bff3635ac139a7ef12618d8d

Manifest digest:

sha256:0c66c142cfd015fecbd2a6fb5dcd3445f468024821b09eb977107412650bb14a

Size

61.73 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.41-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.41-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:ce7b4372fd4c9de157883f9f7d597f781695f8722c5ee4ed285c2c20aa734584
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:8d3980d9b7b3ccb10965950652690ea738e3614da7eef5f49080be1a5111f616
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:3c01cadac3f5ce8263dc2a5b0302f9e0bc17ca67a9df174d90841ca3a871c63f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:00d707a05f4747f247e6e0b257a99735d69ac37e8cf7c9ab4dc56cedf094e9e6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:e4a314711a9f639ae16acb31cce08be49c940408e87895280c90489056bf4933
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:30783e277ed66a8a511041d3c10a033333c2aad1562f03f4f4610378d0f6653a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:3bf6111b3287996ecec2af6bc14cb4129fb43a7e2ca6259ed58b234dcc876ece
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:d7e6bcd08b05c5760b13a9317a52ed11391afb12341a70b63c4a3275296023b1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:abf9b227a04edb65cc2351e856b511fdf549b8122e17078a219ce43e9df1b42d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:a5fb1b0604059ee35b989ff9820f5a2a3e317a951945c3a0c2be40110b0755e7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:ee260bfd6c9668728085025d9d439b99373a0a17e5b0a2a01a095658e6928611
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:d4eb1914930eabb1b9eff2050f6b76ccd1b89090178bdd017a4d1ce3f851deb1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:f259b32da308bb66f285b305d5ebd14a36caeefaac375a9660829a99d9989ae3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:6ab06ceb307a34f6fd645823185a3d1ab9f9e25e916b2fd393229df54d32617e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:fcb1812cae40b2ba31aa6eb99cf3ecf6adb0f998f0e5800ad2a5b29be6e64add
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:77bb1e2748383885f436ac84178f342f3e58c8647fc60cdd8ff46e9f5c606a24
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:6e15a2346bffc42d2f2d7e591e7b8ceaee020041a311190fc7f9c4617c08e90c