dhi.io/tigera-operator
1.41-debian-fips, 1.41-debian13-fips, 1.41-fips, 1.41.1-debian-fips, 1.41.1-debian13-fips, 1.41.1-fips
sha256:ab1814884a0ff8af6f6ae597a7859807ec9639857728f56ff22bbb9aca5f6c23
Manifest digest:sha256:53d3e9d70ac2bdbc04de1271258a55e8e8eed2c7c4de718188dd77c9c7e0b277
Size
28.23 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1.41-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1.41-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:c51eb5c76566200582eda4a74d30be4d856a0e0edb1006f09de0cc109ed50ddb |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:b6bd001b919ef75672305d737ce4fb9c0512c53a8f5b2193e7e4e9fc3cf8e071 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tigera-operator@sha256:44ca9a83a369625a3255987ff68eab204e0a2a48807203983152eb290af1fb4a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:6b6511028212125d0a4f37bf93eafc09c6c179561fe429dc0c1774ef3b6d851a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tigera-operator@sha256:7c1e69267f82b03bd5c1c8565c7d3d10a6266f7b4af37cba78de1f316fcae1a2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:3f3b2c9671ce996956fe0448b7539ff0cc9780409bb04a58aaed56c5ea87dd20 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:7da471c29e7c68e5a0b729bdcf5895a96501a5d13760a978c5c08e1b556a433c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:79d4969649c7ec31fd7bd3d502bbe1e9a5d4c0bc755f75bb9bc48a7ce7239ab5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:7fab55aa7ac37c33670f21892f86232f8c1739c8ba8ee51995910f1fba329143 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:23b4e6cbbeaeabcff6e32898dcc7eb33b1ab1add4aceda71823d202f339f8015 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:2cf6aa5448bf5a8acf94c28d55eefb5d02bab9dc0ca7f1a02ad1494848d7da07 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:f5be0a1d107b709a1f36f0019de90e5e4d7459397e532d70d24a60e95943b46e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:d6117136182e467d2fe9bea1112d1e72a4a19818153702721f1559b7168c5847 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:d3bb58c6742a4dc41f9dc1216ad8946d48d204674c0e1457a851260f43e9db76 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:63f132abedfb869e3024b17b315dd2c939ef34a6fbd956451244f4c550c9fc3d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:5a6004e4e52808a1a8a61eaabf60d49090ba03689bd2684e471f930e57f8ba06 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:2c81d69f81a9b2cac05b593071a2c4ff6a3ff9a146711df4381c7bd8e162738d |