Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.40.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.40-debian-fips-dev, 1.40-debian13-fips-dev, 1.40-fips-dev, 1.40.15-debian-fips-dev, 1.40.15-debian13-fips-dev, 1.40.15-fips-dev

Index digest:

sha256:6c5e2c79265e615b60240f14ba639495659715f85b9a83b2a2bedecdf9a41ed0

Manifest digest:

sha256:b13617bf0001761b35ba30e894fad554c3ec29601504291f99626844f60b5cec

Size

62.06 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.40-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.40-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:afd33333c9553071211285488d67fb31aa8a22ee735b9a7ea089a0f678121807
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:5db41b5bca7266981547d13930c7c0bf26f230e49e22034a3f960a3d5fdf788b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:6620189b53a2a2d2015eb0ebdd73fce52a068798f6e1f2940e111e1373704821
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:ba92fdf1194d195ab0bed22d4d2aca58c251115ea22ff4e849f503238ce34bcc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:265c976c9b7ab6c7bc0a10fab044c95724a8506e65e111db14677af6387c8b8e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:cb6195ca00653c6fcea3ea3170072b6a9b6f72ea2cc2a0147a600e0d4b3b7e0e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:c209a0960e77391b839007d49044b817df96f904df9b631284fafd29f0e9e062
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:752f13cf2e04ca160ecea38ab193418362f897abc53e5e6b77114cbe453e5582
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:8940a264f6c05430d54cc2fd55bfbf1c8e0fc7f9b8585b502d1c3b628aad8e50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:64edf3c99f4e927bae2a5248ece7f4b4f119dd8442d2420889d1a311bb1719a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:3479bd6b5cd141e57758d2d6f9579ae5014dc40ba8c5fcbfd1abcc5e366a6791
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:f8e13dea22e703369bf441e2c73f05a0118e5dc74b0187c160b84e73bd5eb41b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:aab95d9c4d8c92f47d2aa04ed97cdc7811cbba0f84ab11fc20481ce059f85c80
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:df5d957c9a80b5b69551cf945baa8bdc6ad5132da5a63e709161dc404f0cf428
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:a4b29d8183999477f8fe40a86e8a96cf694ddcdeacc28313050e53586e4aee90
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:6d8ac4f794cd20c7e6e49416a3a182b87f037c0c34b09a940d3420bc46cbcae2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:5fe07328559a02ecb1d8d0b6e18e35a025b062d26d7952f97b71b971b9dcd772