Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.7-debian-fips, 1.7-debian13-fips, 1.7-fips, 1.7.5-debian-fips, 1.7.5-debian13-fips, 1.7.5-fips

Index digest:

sha256:13d8324b0954a8f3f307a247d791d9bc39c3dae3bf7a8155e0c130be3448cf19

Manifest digest:

sha256:8bee77bc411e98c084504f434d2330afd1aba393b4788db3fd2d3ed10d48a554

Size

35.73 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.7-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:973f8d2ee37f3cf7c36810aee6f68b449134bf1fcad0745f6e2eb9e8abd7e007
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:8840b6111b2bfe6d85e3d7c9498dbcf75e9ab0f8a6aeb03d434a045b1e4434e4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:3cfc5bf37fb27d935abe2fd7e7588157b5432bad27911da77b8c94c4ade33f02
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:99bcc246228acb12136d7a63655a13bfc2287df553d98b3032b4413036057162
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:1e3a3cab8800c42358787470e095851d6e6fbbfe2a81ec089adfd3a8b265ceb2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:0355698538b2bd6ac54b089774996f07be61a310ef6b6d9a6a7f65be4502fa4d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:3d5fd028a7acea4fb53b9a1e194caf310c0c783cd2159a5db662057051900c7f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:5e9f084b9409be1488683e3de20edcdd49db15d2f315d14be1e01e97605ef655
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:b4bc49bf324c18999bf52bee01043f38ffed9adf85abc2f2ddc78dfc6b3c87e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:70b40ccb55b25a2042e79d37eeae34075daa1b7ad9e6385daedef3e48925bd75
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:8c8de23dcc4eabfb917e2e1e7d774c4533979690b4782e5f2095ace06ed5fcea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:203f3710f71706fa38e77f9315e323a06b4eded4e84e1daba31067f093a92956
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:9369accf2f5da476c806b669ad3afa6794337a4307699696ea7d3a8060edc063
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:0ff0b9054b9bf06e885ff06208483ca2abbf36e3a6e7136da7d95917b0d53017
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:8cfaf0ddf6d67106e10c49858b31021e3bdb656a43d610b50c8b36852f17f45b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:10ebb6f8ef77348b92201f815794ddb9d95c4a9fa21d6d143f681bb868f05627
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:d9971d87d78f9519cadd9536993d38512c7ba758418cfa1a2cd95d51a280c76b