dhi.io/tigera-operator
1, 1-debian, 1-debian13, 1.43, 1.43-debian, 1.43-debian13, 1.43.1, 1.43.1-debian, 1.43.1-debian13
sha256:157ad27bc62a90d2230ae9bf084f36ae2f6bef6daba64259cc3ed1523246402e
Manifest digest:sha256:0a538252304830fab4d8d5a98a1ef4944b31e4b23523e3b47d166728e36be523
Size
20.91 MB
Last pushed
8 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tigera-operator:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tigera-operator:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tigera-operator@sha256:640e806fa483e7837f4f81c1b59801cf96caaa7b2f44a36014107e7fa7d14afb |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tigera-operator@sha256:52bb6cebe72f9487ee750fec3d9442bd7d8178c32624132aef431012b1004120 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tigera-operator@sha256:ea4609095637f2bd52ff28cf6243e5dacf790d6265c29bddd3258135805bfee7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tigera-operator@sha256:3c45c89f51a8183b5688386006ad2dc2ecb42bc199c0ad58df3b18057526eccb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tigera-operator@sha256:8487e53425623a545fdcd3e0dd5cf1b4100c8ca979e091c3fa4fbee2d1a70183 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tigera-operator@sha256:d80016cb034fe79a85e208b0c4984a54431356e218f7b8f5df173dcfad218f25 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tigera-operator@sha256:24f03223ce4203588980db55b8eca4f2e103e222fc8b11eb36a475c2ec03caea |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tigera-operator@sha256:39ba9af4ad2db8e25ae39f57b7522eed38059946050751f7ff91c32ae42485cf |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tigera-operator@sha256:cbd416a086488805d14eb06f9194fc652da61b84a478a9be9a7655c7c7e4e7e0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tigera-operator@sha256:caca0a4150a5751b6581a381920c56c3194d8e31068b5b3dcdfde5ad3661eca4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tigera-operator@sha256:5792fb27a7e1e573443a89e495ef216419359d0b69a03d959cd1ff01a49f0cca |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tigera-operator@sha256:aa0d8f7e15ade0f8b8c49d6339b6105cc2776ac60cb25a752070fd97b7c15f56 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tigera-operator@sha256:24c1f7c1af4afb728218f641b5bf0f4aa7e89f957a539ce1aa2e3296e45e3d4b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tigera-operator@sha256:9d58320e33682b37df3c2de3a6d6699aa87b9c599870738f473af1fb96e76766 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tigera-operator@sha256:89fbd1032b042870182f1dccff8aa4dc548b3753ab7ccba89bf1260815a6cb62 |