dhi.io/tigera-operator
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.43-debian-fips-dev, 1.43-debian13-fips-dev, 1.43-fips-dev, 1.43.1-debian-fips-dev, 1.43.1-debian13-fips-dev, 1.43.1-fips-dev
sha256:7ec1f522b159f4a06edcd6c166e4431a4672c63942d6c1ef63762e59a8452d43
Manifest digest:sha256:57f7c5228299ec2311c8fb81007c4bf469c7deeaf3ec46f3484dc55416c176b8
Size
63.40 MB
Last pushed
7 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:30ed44bc8d6f36698447180c1a3602f0aeafe66264c193fa00b7f6dc07e170b4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:0a83f1d30f53ca96897ae9dc84214c9dd8e5f9fdeb667b14475a0cfcdcef086d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tigera-operator@sha256:3d5e8e605d40034fcb2fb899a7072347c0773754dcf49d72e552a9341a71f42e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:149f7e401d91b7e8ef94a636ca34d4d81f2d5d00720b00c46ec3948dc2ab3690 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tigera-operator@sha256:3d2d241d3ce0aa1457ff5ca7fcff408a160d9b2dc302ff3ffc3d85b3b22d6338 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:6162542c63a3b11c39a93a779f808c38586314fb9a3cc500c2196751dfa76005 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:6090c858709be57a489a96adb2e1b2ac7be421f0aafdef782a1c938dc244efe2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:ac284860ad65e0d2aeacff91d99a2ae9da0e7eb3848515e338fa8c2e43dcf140 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:bdec272a3be51597916e95ef56fefda7b44784ba10c7ee66359e8e19a66b9fd3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:964d08153bcbec4f501e7095a9428055f47f975a8affb3fa9c455b5d23cf3eab |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:f5d045f25b3395721c82b431d1706146251ce5491596a8ebb4c1e8224c5cb658 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:7af5da78eece2402f0a6b403cb3eba01d3cbc3d6fee08769c7c0ebdeaeda862d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:e292800fdb962e756ef0ef89c576de6f61dd34d6dafe92734d0245d2f98a6b1e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:5b1a076091ad46f4246d72472a6cd5399dc64ef5e2951e78712cc4a931674656 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:f2dfb0334dfa855041df9832c0e33f0b767746280737cd9db0e034958ba30783 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:11b06669c6219368ae4de41887699be4438b171c29c4a44cc01c1b28ac934fc3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:704770c8b7a57fd918b8042bba812174fc51f10f43f0f2e06de8f525550ff6d2 |