Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.43-debian-dev, 1.43-debian13-dev, 1.43-dev, 1.43.1-debian-dev, 1.43.1-debian13-dev, 1.43.1-dev

Index digest:

sha256:5dc758949095534960da8ef3210510132665f64c77bafee4145743f203ae9491

Manifest digest:

sha256:1618bfd7637d73540387e2fe381349a81d9e341c8d868038560d081b3fe22004

Size

62.66 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:2b0490185a12b1d8cf56fd2a49fd45fd4ea5bd525a94f449b954e186aac4c8f0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:b5f2ed829bc596bbdb6355662bdf582ca2ed45fd14a132997c176ec30128ea8b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:d83baa9cb2b81adcb93868f1ba78b75c10045ba911a8e7180bf2dc50b534e885
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:b5b64f22f5663b50dcfc47bf7594e6b221720174f78451e0fc7e0bb3b3926305
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:785dbd00b762258a2230b4eee3a8e02b2e1517a2af9ff0d0712adfcf2b5c72a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:6ef0a219bdb2c6c5f5495173467f17b9a3dff3ecc36c7765b1a5107392c63c84
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:e80938b44c7005d692c7164ad89f7ec01abcdffb19a555a49101aa710b38ed12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:6c7f75ae8378d6c576e1f6a2665477ce04465415f85b17ea92e261166ae26ba0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:4437c4f6397490e8515270fe1379efdf53d214081e7cb76a87649751f7790f78
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:c8211ebcf65f2d4ff6a13c98b4d254853eb0ee8322102194278131f9defa872a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:c108d0397622da02ab3c953d78394088386cd79fc64a67545a85f41a9312224a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:b662eaa973ec33da99e885a717ced2ba92573b1c3448faa7065e448038cb7951
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:fe0885b401dff9e219717f20c97be1a7076ee36a5164ad00679585bcad990bf9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:58c0e23c5338a149371e31963ba68bbb913c4b7590853262725533928996a39a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:9253714bed804739ae3c5ed844a4bea89b773de9fc5413c393b310eeab44b313