dhi.io/tigera-operator
1.41-debian-fips-dev, 1.41-debian13-fips-dev, 1.41-fips-dev, 1.41.1-debian-fips-dev, 1.41.1-debian13-fips-dev, 1.41.1-fips-dev
sha256:66af773d7929dc0cef554f43053f41dd0ee887d7bff3635ac139a7ef12618d8d
Manifest digest:sha256:0c66c142cfd015fecbd2a6fb5dcd3445f468024821b09eb977107412650bb14a
Size
61.73 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1.41-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1.41-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:ce7b4372fd4c9de157883f9f7d597f781695f8722c5ee4ed285c2c20aa734584 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:8d3980d9b7b3ccb10965950652690ea738e3614da7eef5f49080be1a5111f616 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tigera-operator@sha256:3c01cadac3f5ce8263dc2a5b0302f9e0bc17ca67a9df174d90841ca3a871c63f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:00d707a05f4747f247e6e0b257a99735d69ac37e8cf7c9ab4dc56cedf094e9e6 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tigera-operator@sha256:e4a314711a9f639ae16acb31cce08be49c940408e87895280c90489056bf4933 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:46b2079f9f142a10369e526bc61e96f3e026c68189840559915893daa3460dac |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:dc7f4beda27da161912d5dbe83f5d7e0a1f8c5a9e8a5c31051318ad949d2e8ca |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:d7e6bcd08b05c5760b13a9317a52ed11391afb12341a70b63c4a3275296023b1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:abf9b227a04edb65cc2351e856b511fdf549b8122e17078a219ce43e9df1b42d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:a5fb1b0604059ee35b989ff9820f5a2a3e317a951945c3a0c2be40110b0755e7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:ee260bfd6c9668728085025d9d439b99373a0a17e5b0a2a01a095658e6928611 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:d4eb1914930eabb1b9eff2050f6b76ccd1b89090178bdd017a4d1ce3f851deb1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:cfec8a30b9674e35279dd460d2f7a7848225d531d8eff78e6da9f53e3cd47f09 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:6ab06ceb307a34f6fd645823185a3d1ab9f9e25e916b2fd393229df54d32617e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:fcb1812cae40b2ba31aa6eb99cf3ecf6adb0f998f0e5800ad2a5b29be6e64add |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:77bb1e2748383885f436ac84178f342f3e58c8647fc60cdd8ff46e9f5c606a24 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:6e15a2346bffc42d2f2d7e591e7b8ceaee020041a311190fc7f9c4617c08e90c |