Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.41.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.41-debian-fips-dev, 1.41-debian13-fips-dev, 1.41-fips-dev, 1.41.1-debian-fips-dev, 1.41.1-debian13-fips-dev, 1.41.1-fips-dev

Index digest:

sha256:04c20d5a708a34d1d5ae0b4663c908660478f7749ea9a411d906f05cae2eb6f1

Manifest digest:

sha256:d2402a54516f8ec57a82a0515fbe8fe4782f900e0257961b0622adb9e0d79be3

Size

61.73 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.41-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.41-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:16972c99a57b37d203f39156aba073f6bbf4cfac359ab21cb91e13c6699dcfb2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:cd31f3769c36c7c668a93657c3519a9feda1b7a56948375edbc177ad27daeeac
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:c47d1d3ad7058a6447ed77d5bdeca67ecc09fcb185f036d2d8065156cfbb0947
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:bbbea5576a1dc893f5c80b51bc59fce89f0b06b3e61d320d47480da9dd864644
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:959fd81df449b9c15d0178fc55da3a20e29ac78fb059ba6c756b91d4aec73079
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:3012d691beb2cbd80b1e30017e334e1c19f4ba8f8659cff3e6749a70a67aedda
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:6293a9813f05342736c56663d659cae3b1db61212391787822372450f2d46a65
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:3967da528e2bdb618004878b7e588b4c7640f0a4ba46f3d0b207e8c76a3fecfa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:e2b7f6e9b2420475770ae0e33389113a0ae79a2bc5d056603632954f56bf1884
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:94d98cd3f851bd18b864bc287c479d7a312afefbea8c3303c2cd1e6deb1a2126
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:f1c5f981f06edb9ba6b076c1c493ca2ea9ed0afe5e811db8039ddfaf1eb1a809
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:d711288886c6d42ca46eea9b7e6d2923754c2bbe3d554be8a5de69ed2e5c702a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:15895a4fc8ece1d17303994fefc747b6789f00ad768f100a9b12eda90e45a87a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:2fba8806cc4ec01208ef9c1f9ea4f06b97ba963426a87d824735e2db5ebc1017
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:1f52e39a69014f417ba996cf928e591e84c118c8d099ca9da389a9c05bc042a4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:c51250e6c1e4ee71a1cc9798f042557e47bb131d040fab7b83b4ad101ad4018d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:61b8a930f181b96df92622c4bfbb09475ba5c3796ff950a8b914ef18d7e159f3