Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.43.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.43-debian-fips-dev, 1.43-debian13-fips-dev, 1.43-fips-dev, 1.43.1-debian-fips-dev, 1.43.1-debian13-fips-dev, 1.43.1-fips-dev

Index digest:

sha256:7ec1f522b159f4a06edcd6c166e4431a4672c63942d6c1ef63762e59a8452d43

Manifest digest:

sha256:57f7c5228299ec2311c8fb81007c4bf469c7deeaf3ec46f3484dc55416c176b8

Size

63.40 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:30ed44bc8d6f36698447180c1a3602f0aeafe66264c193fa00b7f6dc07e170b4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:0a83f1d30f53ca96897ae9dc84214c9dd8e5f9fdeb667b14475a0cfcdcef086d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:3d5e8e605d40034fcb2fb899a7072347c0773754dcf49d72e552a9341a71f42e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:149f7e401d91b7e8ef94a636ca34d4d81f2d5d00720b00c46ec3948dc2ab3690
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:3d2d241d3ce0aa1457ff5ca7fcff408a160d9b2dc302ff3ffc3d85b3b22d6338
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:79377e3d1dc25e66403900c52326e994e8c6bc66f8bf8470432569ffebe68061
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:91f55a47d0c11c20720d23abf061a01137ca36bb46f700688c05d8e57eb2d5c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:ac284860ad65e0d2aeacff91d99a2ae9da0e7eb3848515e338fa8c2e43dcf140
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:bdec272a3be51597916e95ef56fefda7b44784ba10c7ee66359e8e19a66b9fd3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:964d08153bcbec4f501e7095a9428055f47f975a8affb3fa9c455b5d23cf3eab
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:f5d045f25b3395721c82b431d1706146251ce5491596a8ebb4c1e8224c5cb658
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:7af5da78eece2402f0a6b403cb3eba01d3cbc3d6fee08769c7c0ebdeaeda862d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:e4a8bc59fb87472fadaf3e5a1a177c2f54b805426cf7eb47425989f30eec29a0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:5b1a076091ad46f4246d72472a6cd5399dc64ef5e2951e78712cc4a931674656
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:f2dfb0334dfa855041df9832c0e33f0b767746280737cd9db0e034958ba30783
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:11b06669c6219368ae4de41887699be4438b171c29c4a44cc01c1b28ac934fc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:704770c8b7a57fd918b8042bba812174fc51f10f43f0f2e06de8f525550ff6d2