Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.41.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.41-debian-dev, 1.41-debian13-dev, 1.41-dev, 1.41.1-debian-dev, 1.41.1-debian13-dev, 1.41.1-dev

Index digest:

sha256:d2bb218f54c8715fd1c05b4ac440b899d7403c19237d99ba9470c62728c773c7

Manifest digest:

sha256:1898a4e119cc6d4fa783b900a43d612a56d2e1c570bb1787279b038011d67200

Size

60.96 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.41-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.41-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:cf92daea2d6938cefcdcc0b6e61a140ef7c984fee078b539c0d4d70eda166856
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:903ee207cbfa429c64158e88813b7444b8b11f77f6b4c58c156c680abb4d12da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:a8b17bd5fc79e1dacb0b3b248f72e7ada42cd7b1960d1e81e70fbce064d96820
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:802488917d079ba4d634e50726c872c5d718ff96701e0ac52c768828d6fe1e8e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:1884132284042a33aa89347e4692aa60df9a84f5cc6ed33f22614a857178281d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:2ceb35910e558d1e470e731d510128e45f5c50ba94a83d23f9e8cc1c7d9c1f23
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:0ef349b96dec17366b975d6daa6aceda3f1179771712cb51dcf15ef665414a36
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:b2f24c64f76c589ba3e5958b37ae2da4f1c803021bd096cc8d458cdaf9a8b980
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:42a50a55acf98a8bff4cd70ab1aac36d7641bf222b9ea1cdf6ba418b3a6e40fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:c90f27a4e301ee9c053379ac16b432ba19de49d7dbccc6d6c59bc8fca93a572e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:91c378ec32231dd1f6bac8cc7a4bd9ff791887e76fb5678698a9d26354a5c2b3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:3b6254c4dc9ca1676d394660020148f6b9f4716476fbfec66fe9015654f4f40b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:9ef72b22da644c17f9ccf4190d3df9e303e08e4b8694fa1b861f6b27679ee37a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:b8b87375b395acb1dc1a045b90087760fec1235d0c17d7e89aeca70851907da5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:918ec78e2286193cec27ac23a0eaa32f721ca713144f39654de63dbfc9c8dd68