Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.41.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.41-debian-fips, 1.41-debian13-fips, 1.41-fips, 1.41.1-debian-fips, 1.41.1-debian13-fips, 1.41.1-fips

Index digest:

sha256:2acbaa448f50b6b1c995c84e6362c2030246be7fbae5243f2786d3b404841709

Manifest digest:

sha256:3077bc3c3554d5892799a266ca91d5ff83de49b0aeba010f285f85bf5064e47d

Size

28.23 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.41-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.41-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:bb2f481dfc97aa30d20b65409fb6150f7395e3eacc27bf2f09b2810da08ebe0f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:144873e248e3a85c1b471d828813e85c521f5491563f5d895c30fa4646aaceee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:34b3975a53395a54756fa6d196e0db701157280ca5227d8b1c42b247cb2b75f3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:729379871bbdbe265065c5b1b55ae4202e8263164f3a1d96a3ed033765997f2d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:16dfa2c5d9ac7fad7012f4b4b9423371357ce2af356faf5046b5e0920b2d2a3b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:e1afb0ef7a3ffee1fb7a66334b56fb95dd51f627e40553ed1fc602446e97e7ef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:3724cdbdc97186ea8c27952a873c971e8572d758cbff126603dacac82bc54a4f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:bb908ba64fffa66f72bfd8028f4742ebfbc9a3eff98589ecc21ceb7d2d952c44
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:983f507c3b2b1602df62c702cd848c0e86fe5c25fe6507e6324bb0babc1b6a9b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:d700a8316abeadd907c58de43f50026a2596d43e2cf50dc4c3e35df7014f8199
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:ab3c1c8d58de699595c9979cdd8f0fec00671d26b61fdd4510082f82096e1d3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:0fd5f746594984f4ef9faf70a18edc3b360d6f89294b6e4a5c15203af19950b8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:0b4b6a82275653f7ed4884b5537c60a971e7e8e92635fa5c21778678f0decd7a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:490cc93ed400aec3da2f9efaeca5cd9d07774ab65a6998aa351ef711c4f0be79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:df9e0c3d334fa827fea6451dcad2891febc400fa9b345f37308471795e99e6e0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:d300ce838bbe1364164dea30e7beaacc55b398025b525ae3964cad28701c194c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:9118519173eeb080da1c3f55657141b5e58c117c74f2770592c3c14bc5a1363d