Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.41.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.41-debian-dev, 1.41-debian13-dev, 1.41-dev, 1.41.1-debian-dev, 1.41.1-debian13-dev, 1.41.1-dev

Index digest:

sha256:a7d6cffd80625c8716094c0c4ebf804a3bc1bc84ad75e165c5a8d13c6a0649c3

Manifest digest:

sha256:5996b5bde827c3d256fbe6aaea0d4c030ea23bfc57f9e5fb5403edf2f2940519

Size

60.96 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.41-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.41-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:01eb9feea6787b84c3057da16254daad40f372b7f81afb7069e1ed092f6ee767
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:60c534cc4b338cf1c2f4f0c1626194ff610dc956ebddadb16e1306b8a7f9a543
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:f5a1fa1c7b291cc74e4ceb512410c01a23355d822179acc43d3b4e8694ab8669
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:548a1e10435346d65328d5c1b61be275c5db4f4b03c79306a59549460dbf8df3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:3cf942805dcdac6972d2456ecea9290929dc786a8fecadbebc1853aae497c106
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:2d37b141ab453ac10009a53d0cd5398f23391a5be7ef387e216b326945585316
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:8e441c8dcfc3bf7dcfc701e54d54f8e0ef337d27d2929bfc8fd098c9cec56d02
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:f5333c8effd83bace6576211e0ad20f5844d1bf36b2a9377d9b686c66a05a2fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:68760a8d8fac82a3001064409236f3d509f2e12745bfb39fca9c2f32b8a01a05
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:769e8602773f09814bcb7f5e06eeb8abda04ebe2e91786f3e9fd76af0ec4d400
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:7256b59989dd1dfa81f62d3c004c1bdb359e90231f2c584dd4ed3028c4ab936e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:f208c11faec48460be7a4a69a4722be9988adce714fe27e8d07bc5279fc87bb3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:87051fd81b407be64e8d4cd73ecd7a341143e1119e1f4f54f77d257093dffa4e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:610c80859370f7334dc0d7dcc64684e1c558f05a66ae13b9f7f5b7c6eebd2b0a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:250188a780c94cb6604bc32a74eec3d4eb322b355a30e28a7be83478449d5a81