Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.42.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.42-debian-dev, 1.42-debian13-dev, 1.42-dev, 1.42.6-debian-dev, 1.42.6-debian13-dev, 1.42.6-dev

Index digest:

sha256:9562926a4333ab3f3bc3ce1ca81624214d883548ebb33c9cb74d731e5e1ef6ec

Manifest digest:

sha256:ffb177caa3bf74b670159210f057b14ed28a7a1d474329c4cf8e0bcffdfd20c1

Size

61.80 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.42-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.42-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:52c63a3af8fa45c6d558bc92407a3441567cbdc40450673d72d2d38d6f0cd4dc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:374273e117783a7d56cf3562ff70f881c8e8eb6f483e928d9d27778808e127f2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:4cf3a3c154e76b4c626a38484d4db191a480ba700dee43ecdb18f3c2613ae91c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:9fce269bc30cd0fb3b41ff3b0aff5165d50e9f75f86de05a1a4854677296bd96
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:5e9c2fa841ee0078d83430c96302472ffe15aac576449fb922c55241b72e8913
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:9882610d05d89b1dfa471cf7df6ae524eefceb442199f7eb3d2720b79f383e93
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:af390a116958c931e72503662d15a5bbb65e055580aed5f520c24dfcf1dc90b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:25f885658d1ebeef83621e51e2dfdd0712aefeb73c37ce0fdd67d9f0ed3507b4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:d8e29e6bbfaf6c7e79d05f6651d16ff17c5fc01d88771881eaa9f23dea2fd7d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:b87978cbc1427d16c0b3742567d265f63667740b474b48af9d78aa6df4f694f7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:032d8c811677bac825bb0c2ace72f52c4dd35cbb45aea685e22e6ad93c216012
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:a03a86d9375bc19ecc81f511c0b6784ae47bec8db46183a3966ff1891e01085b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:8e467298d4dd3fa89a3646b1a307b35aad48f542877d9eab07b5824e5d6eba53
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:d0360682d58425e8abfdba7e19d8b856ee5fd0be7ebbfe1c371d397bd4e5e35d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:1863bec839730f7503c306f5dd60502eb2a9bca74b8cf0ff8e69f44ad644897e