Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.36.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips-dev, 1.36-debian13-fips-dev, 1.36-fips-dev, 1.36.16-debian-fips-dev, 1.36.16-debian13-fips-dev, 1.36.16-fips-dev

Index digest:

sha256:7d71c670a6a09d8fb0bfd85498f932e493213cfa897d6db633fa1ca6997a36ef

Manifest digest:

sha256:bed72625f06a52e26cc4d2bdacbdafbdafb6fa7424ba3e1ed97fbe94c945264f

Size

53.16 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.36-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:83b2a90e6f82ba67c17c257bf4707ac8e5d4dac3d2229e08e712059997053758
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:e6460c8e0a8e4b0d968a54def935043a2fff51f28658e98ac5b2def5cb78785e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:48d55ca6ea90e6f091d488a72f9462df67adb29ceb96caa0492541fb5beb37ea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:d240ddcddee7ebc17f86d2bf9d32055bf261b91b6c0914052730da3a598763bb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:4f1b6aac84dc897814e9833fff21eda273a63f3a9cf17ae77a25fcf41e3082e5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:a86d3d3866a2fe18f797df6c6add3644197b706464b18b5070f047d5756bf99e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:494681f0dc1fe2cda8e161cac1ce6587ecd4d72e539fe3b57e8b11a4586a767e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:61cbe7b05b8231dff086c574b403e3e5c44ead5ae6a6de17e40f5c024422817c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:7464b4d188d62b870e83656b93329f2628195a3c7bc71a37d044d8b204bbef00
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:e07d598f3b42e32f0c26c0a0453245a4f16580fcb77e35b343c5fbcf3d3f9556
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:bf1b2332a1469f52e2709b02bf7366f0683a10e098a74c4c063ba3c400670255
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:0c058924ee45a5d73ed471948dd6e288dd51cc57fd788a023828277738ebd7c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:af6e586be8f512eb930a12faacec29f34c812a60a8e31fd5a7d17ed9d1d4c199
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:f276cc33f30eb6b0776c8967e5abed865b3aeddac4631ea457e884fc0ffed4d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:0794f7360c41f535e6d7872c911d62a90a56c5bcbb18640517106b91110be090
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:e4362af3225dbdc815d59b574cf797516858b6e6dd62d30d977f5b2a5514fcf3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:2c3a9f637775b5585cfcccffc97ab6b1bca779ee8a98976c743ff0fb99f67870