dhi.io/tigera-operator
1-debian-dev, 1-debian13-dev, 1-dev, 1.43-debian-dev, 1.43-debian13-dev, 1.43-dev, 1.43.1-debian-dev, 1.43.1-debian13-dev, 1.43.1-dev
sha256:f596557bbe6507b80d932d857acd5f4935831f5c3dc4ad7cdb8a42e160cfe98b
Manifest digest:sha256:b7cab2fcfdd56d9f6cbd49aac24b9e3317ce0cab3f9cf17e6e61bbc7120024ac
Size
62.66 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:cde2f376df1f5e0685c0722ab28526332b7e831f7d297f2df11c05cf794f32a5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:67ad3c01ad7afa18d9b6f31ae2d4c8c8d21c21fe5d61aeff71b78d7b0c7d5c70 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:53ea5344b2c29f0c47ab61d416ef0fd7dce2ed0ceaa6938ad03e7fa91791df57 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:5cd3e39c407b0177203e0e5138f6e265090ce0fe0dd2354649b869bc9751cb63 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:c4ef9d3ee82d013f32d4e561e793cc7962c18ba5d96bae08c7395e22c5b41a3b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:f597ed145b4ca71f766763f9c5b4e789348e1ac072c6d3812693b6b02f86018c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:01faa9c67f7e30a7bbc0efe7ddc355fde6297c84c1b03cae038e30d8362338c6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:ef319814a8872f8d9200c7e4501fa4b6836fdc9c522f56317080ea1f9f5086f6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:f9ae30e05cc160c043c03da536da02578b406cf4f8fc279b1c79fd22071d2263 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:364e1247648f0abdb6e0098670f4b6293b94b7f35fe22030277b3d0fca00bf33 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:e51004ede106075b20da6bbceb22133a889f95a33cdc1a25fcade0b29272a6fe |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:3a6f9e32a11316f2462621ecdb509b77b8d3ed8b2ee43f28c0b2cb5ee7776386 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:bc88f0331766cb6f907235df16273733aedf343bbcd890790d324b85816f1599 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:a1c1cafe753154ee1b303058dbe733e1247bc76629e4d55e32f027ff0551ce24 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:35765e3f243d4a9c880310b2f02ff3afa5c17a9f8e6fb8fd38ada443d41a808b |