Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.43-debian-dev, 1.43-debian13-dev, 1.43-dev, 1.43.1-debian-dev, 1.43.1-debian13-dev, 1.43.1-dev

Index digest:

sha256:2584288ae410dff099f7c22799cbc6b595a07d7c0ba0036fd575ad82a5c1a644

Manifest digest:

sha256:5261527b7043f2f4ccb26611c9efa21887683b6d101f041cd4d1fd46d955ab0c

Size

62.66 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:3f7543e28a5c5c4aa3787a92453ca44a672afdf7026787272848369a3ce9e143
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:b73500092d44fba500b44c8e216d19d75b6d05acf1a86777ebd0c5eb6d79249a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:d50265a66fac45a8116e708878d095de8c645917a508557ba43311f982806938
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:7789cd24637c3369628a96a828c9f54cd314c660ed8c46e356d806c71769ea05
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:1e0dcc42a07662b3f9ded24e3a9ebdb4496d90927bb37054d0f13012492a0e81
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:8a78cc4b17c0c153a78ad3f98206e7f6c0487d4d7dbfdd383bce609fc47c9df1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:4199f88e996d426fdd3e3813edf5e2f5455272c0094eab7ed4b6f60bf120ea4c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:7b4a6663d8c5b5ff1592bc679b09d481f2ef83b093b3de7ca434dd5373a784dc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:a491ec8047890e3632a6fd35071a14905c0bf97e552358a7a2feda544c0c7070
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:7ae6380f30678303db02c14ce02e5c802e92ccb049cd0011b491ad87c5200c8a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:72419901236e5ee0478cd93359721561faf5a8e18b54c2cf491ecf541d9167fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:5ac33e68315071b245153d762d5163bf9ccfa2eebd43b1479ea5849fe9bbefe9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:23af9dbd2c83983167c317e286f518854fa430a7ea91d9f94d3a8f4a6c947b57
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:db0fa4d73e444d689053f28783bac702a4bb7dc5b9c6253b95892c1079fe2afb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:7a742b098468f995071fcc38b5b8d3347e6dd4f50fbde60cdb63b44382c02e39