Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.1-debian-dev, 1.39.1-debian13-dev, 1.39.1-dev

Index digest:

sha256:5d9ce93852328466228977cb7b4ba828d6d5c9ea59b9776267b94fe82bbb2d89

Manifest digest:

sha256:00fb84788fd78beb9431c6c022f45c4f525b66e6aeadfb29a3134728e99ffd6c

Size

57.06 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:2d1d772771bf7281732d6d116bb8c320b5b41394767bd5d785117922829e6dbe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:0f29ec4b86fa4498126170dbb3b12a81f913efbf6eaa2c713f60292975a8f501
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:a0351a65a1fb578136112663a6bc68a2a1df788c13d08923e0650da58839f65a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:11c1684e837fd2db337c3b8ea636ed08ec1d68c28c0c646a0cc3c91ec8672bfd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:905c3ccbe3e92f5df901a06f675a9b16ecd727c66d7789306c4735990f8e8666
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:f1eff9d05d0a9ad9f368aae4202c30ae3a9d88a7c66e2a838aef28f3ec4a02e2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:5d0364d424612857a7a6251d282914a6f939fd157264feafb19870b1047a715e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:1dfd0718ae9d69c7dba397362c503cfb6724366e3e43478588f61f1554befef0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:a2137af21199dd9e9136cd3207013e7a6cf6fecfce2ba8179efa7d8376f9f5f5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:924ea54e045da59fd6ed8a749b608cf5ad51d177188d16d233ff89c258ef32c8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:84ca65fc7140f79b3427c29fbc6456993f88834980ecec776a149972f863f17a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:e229b943bbc0315c1a776aa7d6977088a5db021c2202450ed08b1618fe09240e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:063743573266586dfc36c9bbd625737c47944ce93e03f7946e65c63eae4f805c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:5241f6166ff9cb8e39c731ab3aec3d40ace365a4698bcae0b12c36bf6d6c846a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:45415a8e26a7cf037804098562386d35f161700931b440e6b20ff6dc5510f6da