Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.42.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.42-debian-fips, 1.42-debian13-fips, 1.42-fips, 1.42.6-debian-fips, 1.42.6-debian13-fips, 1.42.6-fips

Index digest:

sha256:6bc8218ce1ae4cf7a7da455c34bd722f492073cb0054b1ff5189bf997eac2a4e

Manifest digest:

sha256:a0c6c7de66d240b72546cbc08a1ef7c49a944bb47305268a541ee943d15cf675

Size

28.51 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.42-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.42-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:eb1da124896f12af3403feeae635937035ff2d4d59d51a2422ea42e9e1ea620b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:95a3684dae06092924ffa7cd774e7572a10895ebbaf19e06aaa5941756d38006
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:7100465b75f93d53449703e82550c6a683e5c34f218200127cef8d30aecef94d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:b0dac0bd3120b8d5b0a4a9207184074879aab6d05d9c81c96a9033c777ab43a7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:caf37d193598a8f56519e81c2282f9711a567e7eef1625f6f096819ef7670194
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:25a7034d53fb33bc91ff2bd06ee01fa2f40a2a9beb0249e6b55f32e76196096f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:e4a8340907bf6d122e02ec53312739c1c969d88727b5dfececbcd7b04f5661fb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:faa4908cb5dcf2a9bbab82b39e54f34c4a45a0d6c9a2a7e486cdc703482d2404
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:e417c27cb3ccc89a2f5bea5e62e2a159b3bc4be77c1d1a2389d900b5316d5ea7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:40695d444d98972423d153a85ba3d9e099db27f6c332ae0d4a22a1e1eb5471d8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:fc7aa657d4c8c918e109e59d6ee93457f27401db54b130cf8b7880b3f410df5d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:200cc1416633d00c41619182bc0b7d17b8628ef0283524bba23e08105ba21778
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:162c6976b024a06d9be12b293b02e5d952f21e7ea6eed0e5a988bcc00f2bfb9c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:2af7a9399670d6a379beffde88b1f122126c35a32bc07df69feb74e9fa1ddc0c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:18984d25332732c716a9092c4f19eb4a409b6b5d56ddeae8384499bf9702723f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:361de57a5234a55a869fc3d8a746e10e62e63b33ed43c4ff6923c8ca3efcb00c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:ec73e50867ac1065006dd288685f21ba4b5421f5e4189797642c5a81085b8cec