Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.38.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.38-debian-fips-dev, 1.38-debian13-fips-dev, 1.38-fips-dev, 1.38.16-debian-fips-dev, 1.38.16-debian13-fips-dev, 1.38.16-fips-dev

Index digest:

sha256:d4eea304e8367a81297dcca6e91442a94b1f123d5a74a09941debdbdb987d40e

Manifest digest:

sha256:ab66dbc8eec7137692f0eac492ec8065b2e6100319e88314c114dee6593ce9c4

Size

57.45 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.38-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.38-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:5901b3e481d3a9811b9d794f1b344da7b3b7d86943242082cb296052a8a4ea3e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:a6dbe31d7a74fb3b9be68d9a834dfac4ba8d2aeff8dac62b4619c92cb7d35452
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:bb23717419e19923aafe40dab1471711d09de56166b14b29996f69e765cf6992
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:52d95ae984ceab9949ee19cd8fd0c5d017219dc27adfbaf2c486cb32206ca9d2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:ba45faa080c22c0a46f3a33aa36b0df1783bf69c675210cb6d68aec1ea665a7b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:dc46f5fee2db466aed6b851df3adb525e75d05b55a9e1030ce90dacc3c0035d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:080d846c5dba0b004baafd4dba0a5129563c9104c7dfae07edf854aa56227015
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:ece3774404d87dc57e07e447ea57126b5a471d667883958b13b5366abbfe4572
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:3448f589e159676b09dc99a0e54f9ef3834f0b8d40acc3171fb5d16df799ff10
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:dd5eaea757c24aaf4caea318858acc727f75fb8cfd827a7b244b14886aff70cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:d9956d8901aba23b98aae28eecd40ec5fc692cfadf4ae0a8492ea8d56563565e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:a68fb6d3cf0234a315c503d3da67d8fe386c13db35931d0ccfced192a1536f73
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:33005df0a842066e6b3cca126c24a3980217f73345e49b8e3e4cdbccec235bdb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:67fd836ceeea678cf7a8d6b447b16416eb1d3d4b656bbdc3854380af4fa2ae79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:93b4f5c26deb0fb05e87aea68c2090bb7e0ed1ed5cbc6ce03544c12cc83f3fd9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:a37bf79347507edb5a720894cc3378807c14abe5217bb606c5d6b74527bdc55c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:6f3db6d56e37ef52fa99a5b83ba1d4a00197d5d5b04d15b2f8e4a7d1237abe58