Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.42.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.42-debian-dev, 1.42-debian13-dev, 1.42-dev, 1.42.6-debian-dev, 1.42.6-debian13-dev, 1.42.6-dev

Index digest:

sha256:dbfcabb93db2bf629ff9ea7881521c08754c1d4f9a92bbcf5e685a256e511965

Manifest digest:

sha256:863ad8abbca500a6c0bb44995e99d236a3b95a3f3dd509f63d4c7cd8b9095556

Size

61.79 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.42-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.42-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:54c63d7438cb9969ec969c26363c13904301179d556bcb8a5a24a7efca64c485
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:d1d8b442b32f350945fbe0ea225881cb5bc0c8d63e543049e62505241cd7e859
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:9954173a90c1a3e29c46ae9de9665db31770ef4274115000c5002c188a7fd584
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:0b2b4ae87c7f3f838380e8fbf3dcf2308efdea25ae397392c9bee13eb83d11e5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:688e741e9ef25f97148be1cb923e34af1523ab38808c274048093434b696c03f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:a5f6d362aec24501c08cbf50870f4bc7c450389f76629a7eb6903a13e8c2eb0e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:deb6304b5dcff268e76e2bb1c6c0a8c8fe79bbf5258d82e6497749c310694332
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:33de1b9da4345b103db98377a07f2b6ebd8dec87a57840b4ee13a841b9affeb2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:370405288fc0ce6232d0ec1c4503df7497a4de867dc14edb943df4ada614719e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:c3f53c5705f6fcdeb47d5fb868cfd1760c3e80edf37792bb4048b27db6ba896a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:1c1b20588da95a5f5d02c52b60c664dd6296644a34a15255b92518f188e69d30
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:1a9c7046bc6d14dccd76e7d42d03437071a8b4770f77b0eb4c4bc8ec0790f27a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:9ac8dacfa2c8d57315695c702661a63931a9849615d221a3a71b900f3cabe6c7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:3c3c4bbe0dc50e86b9b0d670920ed44b3124685bb39f2c57f7a74004f5cf5fad
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:968798fa55aa84b063f7c1fc03dde8f867b0f6e8a28756d3845b34044d3b93ef