Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.39-debian-fips-dev, 1.39-debian13-fips-dev, 1.39-fips-dev, 1.39.1-debian-fips-dev, 1.39.1-debian13-fips-dev, 1.39.1-fips-dev

Index digest:

sha256:f6a33803253c96f1b3c339c831ea8d872ca36a5dd03382162aa66ba0e580ca2a

Manifest digest:

sha256:3a49bbae0f314a4470d31ea0c16637d887e0cccfbdba69ff166b98a4266379b5

Size

75.46 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:658eb6ceea1cf66eff5755565d2014dc9655b17289c2f44af61812f0bfd1000a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:bcb680b325efbcd86c7233610537c0ed24fd49c67abcb9faf4b78e714fdcc192
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-contrib@sha256:e9314845810925868caa744e1a384f0eabbb194a170d3048d8a120a0df5d05a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:11b287fc798e28904159a3c8030a713f23ceb3b4659f6084bc71ddff315cf59f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-contrib@sha256:419e8da4d1e835da9aee1d0a6d95ca77cb733ba0b519a92aee251f170b6c1862
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:09e12f233b60c44bbdf7acd973905d80fe4a2374a11e475a87a3784cbc31da26
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:4b3d93bcb146f4bfbcd9c5584b0e39dc8ee26ece68b172580a3802ea0f4976d5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:14d1a267b57350fb53f9fb92c5fc0247bd897580eecebc1c298f565d64950ca2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:0bad35bb55cdaad700fc981ee1bc67d23a8af01fdfed552975a61c1c8fe1e4b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:1c3ec99d7393b9e58655e06c617dc5126cd0094551ca6e3e80883fa1082e5376
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:768e650cb1716ac11f86ef3c9b3f2c1c76b7a8dc5a73ae744d27c37bbfa44619
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:5ed463d0f29bf7515c06153e844dabf8a210882c36c9447607ecfab277fda703
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:1789d5e821771bb9d6d2a87a81089c8c74d1e51037b5ad6706f63488f6bfbb8f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:a8a1bbbfa7f8a0d6499f318e3a6bab89e8a970abffc9e79c21cc4cc5782913ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:3d0068672bfad714d10c396d69eae760d698b0d74c9e84d753b4848c152d56fa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:1ce42693e797aea5e86f5eb04337a90fddb6eaa99eb61305f426026e6ffbaa50
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:f0ba15fdf2b30c220b772c19980626cdf51551c2d0a963903c90b162230a9174