dhi.io/tigera-operator
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.43-debian-fips-dev, 1.43-debian13-fips-dev, 1.43-fips-dev, 1.43.1-debian-fips-dev, 1.43.1-debian13-fips-dev, 1.43.1-fips-dev
sha256:bfef05800c64d62da9e6c8acfa29e2ddc6461f84db8d3af7b1bc1edf016bd2dd
Manifest digest:sha256:6be56ebfecd5edc49ae068b5d4c1b5adfbebc1825bc819dd22ecbaf0f9edfa86
Size
63.40 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:2c561c3425da42b4a636c2684ce4e9a853e04b3d819d2fabb254908288bf946a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:e59c63be071321841badef7d0c1fa94e9fe2def78bd8d2cee43b3e8fab48449c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tigera-operator@sha256:2e186f45dc0b714249d36eeae6a012374eda4d4bfad1ea187c7d4ef487dd013a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:ed3844576c8e9e3098cfa7be435bb6442758cfad3743d65a73f0c5c0feba4409 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tigera-operator@sha256:4a27eec01c99884dc7b8d7fdb478b9dd30fdd803c3f5e1c11d5e6e8db6fa67bc |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:ac16635b3a32b87e26e44b5aff17166ad61ce9ce2d55339b86e36b4b396fa91d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:6f778770dffe76e917e0554e46dfd18e2a6cf463544644b078dac5e602a5bd17 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:1f25e25c381d9b966fa8992605c2cc352fd68f3d761c6781d0e6499c9f5b120b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:2ad0c43b309a11ae158c11e85732c144bf3356e4452666657184da8a7343aea2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:33ba8cbacbf8a6aae15e0e1b17657e801979cdf356ba4a2686ff69fedefb91af |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:be7426547086a7adc59e3090bbe730ab4db2d282ed3951369775513585efa157 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:9747b7e35384d9a1681c6e326c66a9534f1f7e34b9354fcff5c76e7ae042c2e5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:c3fdea939f4b7bc01f9066cb5252fa01b3429b05b8ed365d0f61c5398bccbc7c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:71c90ece70c463a9f5539ff1c0134d0bbd365f5311437bb61b70f0ad95a2fcd7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:d7a8a891a3b83f0aebaa06929dcc6cf5e07f644b57b3ba22b45cc42a30434e18 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:b0fcff336688711c9bf5f8b045b10bb87e14aa19c6fbf419b315df0225322984 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:897297642aef7b6d2ac2122793482a044755f2bd404382c8cdd6e05dc89f89bd |