Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.43-debian-fips, 1.43-debian13-fips, 1.43-fips, 1.43.1-debian-fips, 1.43.1-debian13-fips, 1.43.1-fips

Index digest:

sha256:29f21ab854be98a21bf535f11acdd873cc210793a87f1aa5c8b1c44aff18a505

Manifest digest:

sha256:7ce1125d711b61a52acb4557756c07a2ff5329b08c9bcbfca66ea75db2f3db16

Size

29.92 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:2ab09c9fc661082f5395cd00dae5ef92c56f5d0feb349b446c9a8ee6e4b1c118
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:3bf9fa59e0ce2b61f75ccfab48e7966259e492d5f5fbd48f688b7c21580aa1e0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:30c6b65a582912eb9c732a6831a0e8f9740eebac5fcb67be7e4c2fdb1aaab3c9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:c19ff4d2acf67b285f5b019c41756c2e0f97220711404e8e7196b8a2c9b55171
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:dd75b2a658451d3d4ac4ae73d26edc47b8d5ebb4af4171d15e62b476b61b8ef7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:ca81e1ad9756d62f0978d2be64606c5a2e5a3752782e213e38aa805c270f30dc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:bb33024f24b1486c19d31e410d6e5576fd86ea01212ab99e8d08511dca99dc8a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:c2beea955ee034049f5307fa9179b6041b715f3551d9514a15ec0f7f7d18492a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:2298afeda2b64a3d7bba26aabeac610e758b5fa770cd58bb3b60c961464508ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:9c31e974777b288e35dfc4e5e4125ec5053478726894ce459974e5e8943f0f05
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:be95fbb93db91f56bf13aff6f5463c578cdd1c4aad213eda5218ba786199beed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:3799db1e1ce543699976e8d0f7db1590f5cceb125df650695e8b50eb90c61e35
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:a8718f0ed8bbdf8191a26bc36fb4b7601dd80e135b970efc377215f9d1e63102
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:9d978787f5ac3d3dbc93ae63b7cdc7b71b2cda8670c9dadf1610c67dd2b75f31
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:30d5e2674682e10b9912b648890f64f826429e6fdf01e1a1f1980de19d3bd031
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:57e35e2b28a0ba084f6ac4d6d7f2c9180a06fe14183338cb5aea6464b5161afd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:5f1c4c61f6d012efdf991207a8b91ba52d448026a152ab199b7d0d784667e6fa