Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.36.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.36-debian-dev, 1.36-debian13-dev, 1.36-dev, 1.36.16-debian-dev, 1.36.16-debian13-dev, 1.36.16-dev

Index digest:

sha256:93caf6a1910d496a78c82984b9d9274c53e5886b56bdd4f147c5e4a1391f9e16

Manifest digest:

sha256:77e23c9552a721548c4bdaee64efc35a59aff00d6cdbeeff1e37de8b50859801

Size

52.39 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:bd59f937535066db5c5db5ffd382f4b022d4f5456b464c37c19c17d30da1199c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:adf291845bb2c614f2ca0e442af7dd700834b3971e2b1ba573dfa8d72d68c046
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:47ce35fad5b2b12ee01f586772ab1aca7390efec63c428816ca8743431fedd25
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:71a50d1f04a6e372cf0502d7ffe20e572d3939285f9380157d17c72440f8d8ea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:b6b99a0d8fcb97aec0a893d03c98b72c3de0482ca1921072270ed3b1386abe98
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:2e31579f32f67c04bf5548007e580dc80dd1d37bd812dffd94a3db1a44f8ec3f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:3141dc0f3997a2ddc8a094fb13fe8018ed9aebd89a4e0ef1f662cb6b50ba94a3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:4890d8518900818ebb097268df9be193b281c8de1d73844969cd25c6cde5e1ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:c7645670c55008a8cb2f3dc06f4c368861470df123114634d0301892d66499c5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:fe92ff4b648e657204b6994b0b1c4744754fbd13f99071dcd843fdb4feef2832
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:94791299335a2444968acc3e40a749128fbeae6a7de74451b86d7492e000eacd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:448f4ca7993faa86f03d3e501d3f9369331b073b42bb99c8ac3ea96a305fe703
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:c1231b9640dbb46ebb24defaa841aa72b29ba3fd14915e7ac556d0d7865e4984
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:6f773fb4d54867847d4b73dd3f9b26eef4bcb8b0b3d739a52a973b10f87fd1c6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:b1cf9b042289452ea10279b3ea199af7a7351fe069ac11a554cf8c7fcdebefd4