Sign inSign up
Tigera Operator

dhi.io/tigera-operator

Tigera Operator 1.38.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.38-debian-fips, 1.38-debian13-fips, 1.38-fips, 1.38.16-debian-fips, 1.38.16-debian13-fips, 1.38.16-fips

Index digest:

sha256:79499f98f88c017f45d92b1bb249e8450fe09ad5a48d72c95018f3f78cfa7f2d

Manifest digest:

sha256:5ea21616729fb6ae14bf725747d6d3bad9e0693c9db8665a60f987508fcb7d20

Size

25.85 MB

Last pushed

23 hours ago

Vulnerabilities

1
3
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tigera-operator:1.38-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tigera-operator:1.38-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tigera-operator@sha256:0ba621dbe5e88918336d8f2feee564e6b6b5df151411da4bb9d17cbd19764504
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tigera-operator@sha256:2ebf5c908216a111f1dedb58b722f49dcc3a75008514545dda6241c634481336
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tigera-operator@sha256:c9fb102a152ac5d9b9c89c143566b6b677e30ddf767a7219cea75cf2b0eb092b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tigera-operator@sha256:430401e1337fee2ad7e73ab44476d248a76e7c1ee88089992639f6fc9e2a8448
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tigera-operator@sha256:160d1278d69a1151b4d4cc78aa482d7b312a6af7ae6b397e37bd9c2fb23c50df
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tigera-operator@sha256:1303f739a1deb2eeb581a170d035af6bb482205f62ae88c5d21062170e1dcb48
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tigera-operator@sha256:e4bd3ab437fa42c49c2a6e3d52f6a44857e271b6ae73bf41afeef7098ea50e0d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tigera-operator@sha256:998446da887776d9b53971286aa36fc86ed8bc0eb1fc6c763a8d3656bdf7051d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tigera-operator@sha256:1d677bac3f564a85776bc619c36b5a02b6e0c816f3f8c3df7c373a1937e52eac
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tigera-operator@sha256:d1df38fca812c2f3a51061236d31d11113eb600a95995f6e43f737adadc443e4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tigera-operator@sha256:bd4b5a37a14f3940af2e1198505ff8f912831deeed260fc82cc2b1322aac7870
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tigera-operator@sha256:6c0955eeb9429876a71cb44c57e5955babd1549e6213ed10bbca71558a613b87
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tigera-operator@sha256:0d2119a0aff187059390df32a7c7c4ab16754285aa8fc6b99e95c2c5c4fd3eda
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tigera-operator@sha256:22891bb1be6f05bb13768642a6d842720b5b81c43946c3393b07d5c1cdcc2bb9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tigera-operator@sha256:0494112beef5febe7d4f27be600cb270d3af965dc86b4371f0584de72156d5f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tigera-operator@sha256:745c30dc7be7aa6ae64464d28802d48e06837e20c0123c1afbaa87af94762cc9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tigera-operator@sha256:9808ca266772e4542382ee1d0b85e19c57de326affaf903ca1d05926cb3d4ba6