Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.1-debian-dev, 1.39.1-debian13-dev, 1.39.1-dev

Index digest:

sha256:0a4e7b6f85d6785c74c14fa52ab2f1c83f7e94cb0d925900b14f70b4d891a041

Manifest digest:

sha256:56c34b0daeba7701c39efc1bcdd8df1126931ad9f4ba7238984f570823610a7d

Size

74.43 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:693923df390db7cedfdbfb77342d0d8737d743406134e69d3e23c1dbf6f38fba
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:8d1bae78ae5c52073b7c3c5b7f65853dbefddadbd5fa383f7ecc1cc596fa8906
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:10ac685ca0af25ac80cfac42498bdb119960f321153c1ba2e112f8f553a1869d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:eedc40c4871f5e7159fa33a4b6583c80ccd98925ebe22dad057772ccee4df4ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:d84ac81c4fc677ddffd0b95b4e9534a664201e80ee0c5036f0d9a3b6b0814c17
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:e6e6f356d783b006b90da9570219f0d3e35e2b3570cf68fad13ef642efbdd67f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:00d2f4aec834c3c264da16cb7b6ab7080d77d07b12dfd40314f7d52cc74f2bb2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:85b9cb5bffdd92c15257cda81629440022c00c89bab1f87ca02d37fdf886d7b1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:b640729931e97fcf3a1a38f980d8476c78c8eb071ddbd7dee2ab4b74cb8741f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:15f78fc13ab4bc2175353578521a1c99b0e5e116de179bcdb42818787ec553c6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:64b32cd247fdb73f3bf9ff438142fb33f1173e8c43b9b7ffb4f5a327414f5e20
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:732d11eca4f2004f24415ecc04dd83065073467ed3dda8f62bb86a8796a71ac1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:10c3a67a67ece2604c212254c9a8179d61adbf2542a49ef92cfa635a5805d4fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:daf7a4df167f5235e896a77c79b151ec0a79ebd9c0c5cf04435e1a232c33792e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:66e49a2bb491e30938b55468b5b2809bb2be84f3f5b8acbad35d228c68dc4779