Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.42-debian-fips-dev, 1.42-debian13-fips-dev, 1.42-fips-dev, 1.42.6-debian-fips-dev, 1.42.6-debian13-fips-dev, 1.42.6-fips-dev

Index digest:

sha256:a529fbb93ddb5aeed918647e1887106fa6b52f3b37d903582bfeb37ffcb15b7a

Manifest digest:

sha256:c50bc41b09362bcd76c0277b1c77038d911b56d2ae8215b866c136c460e68229

Size

62.55 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.42-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.42-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:da600ded9ff549b28ae70a54ac608b41619467b3dd4c6024efb94cb2f4ef72a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:87a09d13a45bf6500b782b5d4a92b1e31aa9441c059489bce2104eab2b271b61
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:ff691c22a9486a9bc83e8b0f4fa380afe21cafd2c29693afe04dc318f2baebf3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:03ae9d6aba57e9a51d0b442ad9459830d396488bf718aa0204a9ef8b24a8b450
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:4b03ad1065bf1a0996b69b01e8d969d68f50099235b7bfb022056b5b217636cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:1590b8fa8b7d45c4e03b557dd40cf4a6e159b22a2cefcdfa1c187af4380733f6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:3ee0ddc999ea9c68505460c2fc6372044a260bb759d400e397b566c6794198bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:2473adaf1f3327cf313c397493275646be0236bc624f70bb98ab9494ced3758a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:3fb1e37384292988dfe4782d6046471c99cf9e87626e3dfb40d6fc3e1799d606
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:d5215183b27784179132e5a2e2b54bbd25ce24ffd4a99409b6f8baf85181b99d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:a272e13d1d6ab078e2731ac2741e69f7e48a8577d93c200b11f7b5215b10116c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:b6e92bcffaac3b4731040e2eac3efb4d8c23f94001c88ffdc5f1150264f0855b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:378fbd2e77a8da58b8026d4cf16b6b9ad5d9261eb4b6102e25b6c4a196470dd7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:7e6f22999738941f3c9731f59124dc35ecb35c0337721437efe2226155533061
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:dd4ef002405d46bd47de86bea7c032c3828277519728dd494661af1efa1227a1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:13699de27e8cbd29cfee9ea50b90abaf7a23837f477c709f3b1c1d3e7f504a2e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:6b6a877fb079233c6328de359ab6e58d70470c83a8c7ec02055addcb69ad4977