Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.40.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.40-debian-dev, 1.40-debian13-dev, 1.40-dev, 1.40.15-debian-dev, 1.40.15-debian13-dev, 1.40.15-dev

Index digest:

sha256:7237d7640679d11c87aad1ed6acbf589b49d7f52d26fcc0c13feb9f601de7487

Manifest digest:

sha256:79dccc9aa79e401fa10c42d3a091a37a6ca51eab22c8498c7bd9669f57068e7e

Size

61.31 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.40-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.40-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:dcec2d0c9dc1f54533aeb72109b020f1b16654a166c210cc3722af57e2bdf5cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:6e7213b86650a6b6de05075ebd60d4c6dd46afb7dbf9003c527494f82d11cce0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:9a6998c16b11afcbc02b9d855673c581ed1be8260f793563ccf259af12f33e3e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:f0a54d57927e08e145ada8aa79ceb826478b0a5a72435544e4ea6e4361c8d99f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:7df444a0987f34b6fdf22cd1e0cfe4f41402e6e1cec17b476bdc35c3c9e503fd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:e00edd3c059b87a9096e9bf7a404f09c5ee9063c42b445718baaf9bee3fe974a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:3386b40838a2ec9a4fe81695154c1117c3f3ba8b573bdd2946cdb58faa86467b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:d2efa6f881f39fd75ca4aeef86b9659b6530e0cce1ce62a129776706d73dbc7e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:73504f3515cdcffb18a0e7b2c5dc45e652924a01709c26381288e7b741c602af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:0e3da4c5b9c9a17ee3be2e9130ffc4baeee73bc1b3573ccd6d262b9f6aa7e646
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:d461944639668af5f58240bea3f9c89411aabe13fcaf5094dc4a06a0d00fa1a7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:3616e325dfeeeafda23468ff6949b5e123768e8896b9e3b49e1388bc623b649e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:bc7fe7301d39336c13de4f069b50be705faa14e7713b519c4e87cf983be3eaea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:1df10a68d29b86e48a79010c4406d68d2ff016fd47be44205c13817ded1b7434
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:580658d364d9013c23eaac29890dd24c2d30831e336e9b4ad25779a6c887fbce