Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.43-debian-dev, 1.43-debian13-dev, 1.43-dev, 1.43.1-debian-dev, 1.43.1-debian13-dev, 1.43.1-dev

Index digest:

sha256:f596557bbe6507b80d932d857acd5f4935831f5c3dc4ad7cdb8a42e160cfe98b

Manifest digest:

sha256:b7cab2fcfdd56d9f6cbd49aac24b9e3317ce0cab3f9cf17e6e61bbc7120024ac

Size

62.66 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:cde2f376df1f5e0685c0722ab28526332b7e831f7d297f2df11c05cf794f32a5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:67ad3c01ad7afa18d9b6f31ae2d4c8c8d21c21fe5d61aeff71b78d7b0c7d5c70
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:53ea5344b2c29f0c47ab61d416ef0fd7dce2ed0ceaa6938ad03e7fa91791df57
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:5cd3e39c407b0177203e0e5138f6e265090ce0fe0dd2354649b869bc9751cb63
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:c4ef9d3ee82d013f32d4e561e793cc7962c18ba5d96bae08c7395e22c5b41a3b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:f597ed145b4ca71f766763f9c5b4e789348e1ac072c6d3812693b6b02f86018c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:01faa9c67f7e30a7bbc0efe7ddc355fde6297c84c1b03cae038e30d8362338c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:ef319814a8872f8d9200c7e4501fa4b6836fdc9c522f56317080ea1f9f5086f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:f9ae30e05cc160c043c03da536da02578b406cf4f8fc279b1c79fd22071d2263
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:364e1247648f0abdb6e0098670f4b6293b94b7f35fe22030277b3d0fca00bf33
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:e51004ede106075b20da6bbceb22133a889f95a33cdc1a25fcade0b29272a6fe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:3a6f9e32a11316f2462621ecdb509b77b8d3ed8b2ee43f28c0b2cb5ee7776386
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:bc88f0331766cb6f907235df16273733aedf343bbcd890790d324b85816f1599
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:a1c1cafe753154ee1b303058dbe733e1247bc76629e4d55e32f027ff0551ce24
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:35765e3f243d4a9c880310b2f02ff3afa5c17a9f8e6fb8fd38ada443d41a808b