Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.41.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.41-debian-fips, 1.41-debian13-fips, 1.41-fips, 1.41.1-debian-fips, 1.41.1-debian13-fips, 1.41.1-fips

Index digest:

sha256:5f8fc0e207f1f2cda894e1908331e720d6278656239ec808de4be0282f35d071

Manifest digest:

sha256:8f6597267d0e6a62f1e6e8fbc7dc3b46a3b1775bd27253c656f08fd2c809c79b

Size

28.23 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.41-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.41-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:c7e01e51aeb40bf89a8f5a9b4f0384c518cf6d82c6688f6095254fc034826988
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:bc3fc48c7e32ae1cb9e2bf41071da5007d353f94c2171a2deae427f5afd16b74
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:16a8bb757086d8e16bd784bff98a0d42a5c43aa99b0a26cf989dc4452f0a60fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:5301f5cff17eb429f1dde8d13ea16f1acfd6bdea61f0a80bd190a96a23b85f70
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:dc0586faee2787174eecf75bd83322efe56155cf90e11239a430bafea35ced1e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:6591921c905f5e3d97c89aa49a97efc2d1a7bc76e70fd2f89715531813ea498a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:8a62b64c4136d86c5f0883eed837c691eceb9ba14725a3c1662fccf342526485
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:8e89139118682a500f42d1860ff81882b4ff49a2a0d08542eb9377a324421fe6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:51d41dc9c22334a0da95e4a1de88864a31e18b627e254990ec1a965b63e6918a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:83e32d543cc5efcea97ec1631252fc237e583f8ca9094f5f13027d78e093505f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:981c9e7bb81e8f739fa4d3b7bbcc9f7c94e2032f6e61f7d613d518bf5778d0e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:2a8f474dd86a2f4ad1fcedddf0aab18442679c0c3d0fd9f21d0543a1d6a3dd30
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:e212ded026e9c2b92f3766c052edbb99da668b012a9e0db4b82cea08ba72c66f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:5937681cb812ea3dfd56d4d5d2638e2803083cac58bcc64554be3c0b71e4491b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:7f268c1ef3c3c4ddc609b09bba7848a460e4ae7a15d4da401a396c90cecd1ed3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:47a824d4cec7ae04144b27c6a36f150947b02156c36aca87c8e8fe81f820a1c9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:f4979c1f6262c77c89039abd3f87ccde5818f6084526d68bac13e26acdfe2b26