Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.43-debian-dev, 1.43-debian13-dev, 1.43-dev, 1.43.1-debian-dev, 1.43.1-debian13-dev, 1.43.1-dev

Index digest:

sha256:0722b9904928d159c0ab0c192c43c15caa1b7284988c9311512903acded38741

Manifest digest:

sha256:e2e057d31a8de735048f9cc821efc05c65529fd9fd51e671c7cd128ff3974a7f

Size

62.66 MB

Last pushed

10 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.43-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.43-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:0098634709e87eaa667034e4f5616cf133362065ddc593b10bfb15b7ae6c0cd8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:89c22501c5a5140053aaf4d75becb3c4e1e0519cd5ee391ed0c3f8ecb64fcabe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:83dbddd07c5ad326b577c694f381baa53b83399677a286c6a74302b8c2877ea4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:068d9104eeadeba2ec2a95c7ee88d348a9d62d45771f58c5cd8a0722e9612355
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:c77486f7b4b60591ce2749ac04c861282f75c339c213e2fa887f3759034d9bac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:5b775c3fcfa2631bd244c5c0f51812cb5f88e7b64b8f781a3ad0e9a4df1bbb91
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:c0954235c05407f27a625da8b1231b9984e7e626f50162cadc1ae687d6692aa5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:5cd9565e11287d7b1f5923f4b6ad2a5857fd56a04aa086c941d9c18171802946
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:26cbf0dce36a7fa8168579848dde41a863135a58022612b100e848c6e0eed1b1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:9fd032a55594f43b0f254daa457f0add8dca6d743e1f69e8d55d88576bf80493
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:339d8e590f55c2e7a7e422f991db325b64f5c063258bddb13ec4f7f4cc5de376
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:98cd0444fea8538d3d3277e0bb463e5df9be5e9d1a52d18f08a21d60e8da1b40
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:e94269762e3e0c2025cae68960933ea7ae96e98e516ba06faec05ff6125812bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:b983ba9c6eb04d069ee838a3e7e1497d888325f7ef773e083a7cb86c38876768
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:92eda036d126add981b8ab158ef591e84ea6092be84f24f7893bde0e91d05824