Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.36.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips-dev, 1.36-debian13-fips-dev, 1.36-fips-dev, 1.36.16-debian-fips-dev, 1.36.16-debian13-fips-dev, 1.36.16-fips-dev

Index digest:

sha256:3adc3068c15cfa8806055afc2b4be38e1cb5f827f542ff504290d1b7cf0b3a1f

Manifest digest:

sha256:9ba48685adf3ee1af5960f54f415d3c516a784bf5c75034a5034f93793d73174

Size

53.19 MB

Last pushed

20 hours ago

Vulnerabilities

1
3
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.36-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:a813f5786a6928d7e533f14af8e34d5b634df9a6a622a52dfff1c7cf367c3f13
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:967805c702b186feb8209e406dbe2be37ece61724ce676461954a4f28a670b9a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:01a84696b0f1387900f77b56d575121e9a6d7b6a85383049e7bc67d517d7dc80
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:58384c1b011c6148a5e65e69f95910959660a68c0ff04522979b00eac05b6eee
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:a33d064edbeb08fbb828de20dc79ad4d0a7c93bcf5b46b0fd585b578ebea0632
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:ff20ae78b2ff94c4e168700b151d00995f27d4103ad1aff9b8a7075556d34dee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:09751f9bf1af2aba535fbdbc839e3e94d3fdf0a1176020d0eb4303cfc71948b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:7b71093d5f2480bfe0cf02ef6dfa3b88544361315d949d0a538d77668016e8aa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:32af7cf0ac3c7e2b93e63a4ef959b67d548832b04ff1e37a0e8a2dc7a577605d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:7a5663572143538b7e3682448517da9d004eeab0cd04e926e0681b5360d15a67
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:9070f5ee24dcfcfd44b739feddc60f5d5efd738c7e1e6da64c35b6ae776c45b9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:7cd0734435c11930659e931f0ee424add803af3981107e9ccf76f3ad07b0185c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:cffea93bfc419490f8a5785f2087fb071864f44fa0e66c9a52cb18b1bf8ad042
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:4777a5a444b5cef1d63f3b02c95efb184a4b92a258c1f4ddc1f5c97c55855931
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:e98e1fa00f1f440a5a2536b5f79fb59d214f8530a2ff9c654511dbf3136d0a52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:7f284b19516e49c9d5f5e8b6198ac7f8d8c7a1822eceb11a7b1844a17a70a831
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:cf2af362beb4e92ad1ff85f48ab6105fef7bae7b57826f8c1b4178199b36abb3