Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.39-debian-fips, 1.39-debian13-fips, 1.39-fips, 1.39.1-debian-fips, 1.39.1-debian13-fips, 1.39.1-fips

Index digest:

sha256:d47094184a025dc01497ffeccf6d756c8036a4749ff46088931af85931ef8aac

Manifest digest:

sha256:75357c8af83c205924e1430edc94a3ab829a3e3058168a5b6460ce7b45211abb

Size

60.42 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:4eeaa2a67a0829ed309bd5d3f186e89a92db5a669dd385673be2a5def6c092f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:b4521b139db687881f732d2c25b65e7a2b8d984136d63dac59069b3e8bc08802
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-contrib@sha256:5116af966e5340ce4961902c6e8b1fb8d372860b6b6e29bdae2c23eea92acd68
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:88c1153575f840123231ed2e41fb4285eaabfa2f4c09d331bcefc1603b978958
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-contrib@sha256:2473bf769a0c8c8897aa5c52c28fdba21ad32a8564040e248d19c20d2e8f9f33
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:07b38754364b9987ee9db4e7a2f04812ad980fee9871dc1e8f9a8d1363b3ff9c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:d176a2b849f7e6b2827dc2b09fb5f16a94ea5db43e74074ca22d58587ccd14e0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:56dd70935453cb754219c1fcfe6e9030f1dabda71db4a913fa29ddf57b35ad4e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:5b61343334e4250edbc491ff1fe0a2fdd7ee7feacec77d5090e43ccd35d673c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:9a2d56dd777ca432f9abeeff2edf5a4e878e0f3f1c0128081ed9558ec36217a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:e8f7c94d514de9b1f980a2281e8558e06d1b69bdc241e13a42eeae8c966eb5ce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:4636bdd2a7c189b7d8885bb5b6d2786faf91002bbbb7fa0fe08d6dd17e1b417b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:dcd805de126c7b502ae179d78584220e4e94402b1df2370fa6aa11fa9e8cc852
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:3892baa80c4ee55d856e9a46ebea2b128401c2aa5eeee10489b004b576c5d79f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:a4d030d66745511baebfde24b36b11041c35408b4d548f7873401495849c8623
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:82fb621cbaf5eb42dc028efb36440b1a8cef1b8234ce964f0aebe3bde3a8ae60
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:0e58f72b3e1b6a9289f94995c70546299651996871ee9af770f55c9463e051eb