Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.39, 1.39-debian, 1.39-debian13, 1.39.1, 1.39.1-debian, 1.39.1-debian13

Index digest:

sha256:344e7bb51c2c8ddb85ef9f904ed8ba79fef43122b342cd315dd9c6c626e273ef

Manifest digest:

sha256:761a970763dd92db04df06d3e89112cb785ba0ce24caf4d0cbc3fc8d21661f47

Size

55.26 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:3e7390ecbbb0e3db8e347d0a47863e1de92bf0aa8e757d4a71be6ca5180a1724
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:628b3fa817c762a07d38f0aa5c2318bc7ef0b96ba2954d8651a8e4654563a2be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:f7f8bdc390bfff6e81e56fe9ef84e2a83d7a50761088fc1f8c2a7602b30c1ed6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:ca6bf1b3406a01698fc491ad02fb3e7b2890d12fa0035e9bf2d3082f1ffdbff3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:d3030d613f46f30ff531a65d65654b8874fa558b3ebfe52a15a247ccd71844d4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:6b55b1b5c0707b585f08f76c02d1a70f113c72299fb169dbbbb30c34c9f14010
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:eccdb9ae71a9f775c0e361290e90815fd33077686c4ef9c92f67384d27799964
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:3f03af07045b3fa6e561961ee26de50ecaeb4c1c5ceec6b7d59198e8768863ea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:e3e487e28c76245f3d3fdf1c29e92d10883512823ce34449c4f028bd86001bee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:bb3a1f5e883976615e924145142439069537f97c7366ee08c4fd064ac8d969be
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:21d75e089d1188a0ab1c24cd79488a76718c30907db66672d7a86a0bf5c3f54f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:91267fca87c3360f258d2db661eba0611f8b1784f8e4c4ca45e9600e3decc902
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:d22c1e40475ade3082e36adb07c7429b6806eebaea03293506f8d32aa1e7f1f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:7d6ff4cbefa282bb04a38608165dcc9fd1abb6c0c3318daa0cc0a7b7bb7dc2da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:c00da08e61a85c98e72ece16bcea515accfae4fccd5324199f9c2ab88b793da9