Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.43-debian-fips-dev, 1.43-debian13-fips-dev, 1.43-fips-dev, 1.43.1-debian-fips-dev, 1.43.1-debian13-fips-dev, 1.43.1-fips-dev

Index digest:

sha256:e6a41c5993c847558294d443e82da8b0c9b4ea958dbac7ef76d115ac4b78a1e8

Manifest digest:

sha256:59145e752e401052feb51ceb65e5136fa3ac6969c1af3db3634d611189f973a2

Size

63.41 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.43-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.43-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:32789da3a1f6962d9e36ba0e23c182cc521cbae97de74544b7627a61d8c285e2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:1a4cf6f6672e96f7ec6a6e9d77c1a52f6f5c2d19ebfca4c4de4d07383814011e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:a259556b36d86234a5bb0bb991905e501b4acfa055ed351e1c0ec15ef4ea3984
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:802e54b6a496acd3f8389f7d9526ff9d2191a3fc13ee1e5bd3d059a462e72772
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:5febd832d93066090e8b78030e4794ef4c6042a1213ade553cffc16e2dae0c54
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:63eaebd1cd70472583026c1f536e8accc9e510ffb4b892fac24d73137ba16eea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:b0023e08371fadd9f75c28e79f665446039d12e52c069d01e674498770e5d878
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:52e46231ee433a89277632ab189682896669812f654afa638e7b2d1c311c59c6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:31581f57c14f12081a06978e4623c1f17848ac09252958fe3182f4c58aab69a0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:4706e45c45007e2e17a0f120969798f1b517b1da4f1fdc2fb159b2e3d0631a5c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:a4490902e92bdc78cf4d2f902ce03b6faa5d236a1b0624d962fdfd8404d8e9eb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:9fef9c3873d2dfa352cf8b23f9c4eb7b5971ee2eaefbbffe0f58eb47a1865587
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:7c46f101203b0b025f2dcffe6c95459c2fda7810cb4a365e83d5814319e125da
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:dc0ee76b92dd3e7552eb353404e9234859830eeb01b5c1de057c60c9291af4b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:50f81ce99e35e1a31b454963bcc2a88cb28cd2cd8469592e240c343bce75160d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:a45299bd1c1d9902ed04a559015662d407d96e64fccb07534429e6048de7d353
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:13cb081e5abbdf2156d34f2da0235abb2f1bd593e0e990e337c4ac13f859bc65