Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.42.x (fips)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

1.42-debian-fips, 1.42-debian13-fips, 1.42-fips, 1.42.6-debian-fips, 1.42.6-debian13-fips, 1.42.6-fips

Index digest:

sha256:6ead6c6e608da27a172b33528dbe218abb7f68834707c3eaa934f5e51d9a92c1

Manifest digest:

sha256:112ce3af5f8922c08b59fd92c7c011e0723e619bd09fe63c0b3a6aa7314cabab

Size

26.32 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.42-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.42-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:e60577bd7281737ae3a9867e029aac810fae383885fa42ffa121ebf876dab906
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:4072f8945a60651b2cb97aeac2cf676469529b00617b26d163c3a6875f945ccf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:d42672e4755241c235954b47eba8f30d3e94278a5dfc3092b866aa702dc7d592
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:7d9a2c24c73332020419856f0968be14ca1465e41da27ad0c69106696ba47059
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:47717830302372040695bb2b56c0983df9f09e8f4c6ec9122ad44a336d385be3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:74c549cb6f482974d5cfa8bd856b6749a2a2491adf501415921740aebe0fe2e4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:cb601d90875b55717a2aa1fe22058abb7f733901a2f91b86e3b048b2a80e92f3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:598bdcb7a160cf3ab6cc3eca9bd144f6ba991b1816ee7618884cb9c120387d76
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:d91f65a6a189ae02f4b549cd25a1d8d4ed7d41a7cb0e0bcfccb9191f618ba617
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:f1ad905de33d565bf20bd90fbebcb03b852ab2cb39956f0d16459e4b92d2cb20
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:6d4fef6cb61847187d1c503f6228b143a8fd292230792733dc2eff1b6a92cf23
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:33ccbeccdb3adef6b49248632a96aa5a2adedd6ee88c4e8463d1a649279dc92c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:d3d53ae9d39998bb9180cc15242ab451e1185c707ef440a519c18183a90c4031
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:e7740df73aacda314ec54fc544ad3084399a46ac144527d32ef6319bf293c823
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:4f50b15514bad36a8664366a3f44cf28e80f99ae82e24848dfbd80fd37884dce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:7c4f71f1eaea1c2ee282d54e339ad3406767c9b42747776f7d38b08e5a9705f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:63d3cabe62996fb6827b88ea3e4c5541a38a13987df222c7881c60a2552497b4