Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.7-debian-fips, 1.7-debian13-fips, 1.7-fips, 1.7.5-debian-fips, 1.7.5-debian13-fips, 1.7.5-fips

Index digest:

sha256:e1f378078a2a26afae4bc7ab616c5bf1811e599ef1a1828d76870b2a0d4b99e4

Manifest digest:

sha256:f697d1947d3d480cb26fc7d43e9b732ed8d28a8efb46534cd28c799129c8c59c

Size

35.98 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.7-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:e7122f56eb0213281bc0e15b8a8108618648bc3453dbdea4edb7501401088d87
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:17561322826de6fc798027e4f23be3f78c23893c1dab6310271eb7ab8dd678c3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:5b0c54ad090bf69ea858673a2a822ea5bbddfdb2c31a01a6e4aa5e097648b892
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:628dd7f22bc4c7d5e866d8153f7855958ce48be10d4274b05b3c98835f7c0913
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:9175b85b8d9f0a742c15092847b4d6ea2b3544beb3895ca6f05d4e2424225201
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:7ce1fce0b767668adc64a4252165c6ece34aa58441a72db7bf0e2f89ef86ce3d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:ecd76bb98c89f33b71c2a8f55dc97c8e0b8126a0a5c3c106f9c3b5705e22a8b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:5da01a574fe520b3aa29b0014c3d5360b4b696e6a5ad4532546557c4cd2d38c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:93e68477085be0b61fbde8d05f4fab607549a392770e4bf6937f5debd98e1991
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:10282b76733374ea932177343acd91af4800088d5901b6e3b02fc31b4a305c84
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:e1b71cb98a9934ed5bfebacaefd4e5c138bf2c1d894163bab9a1a5f88d6c1242
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:35eeff787c5f55e8923d627ecb6d03e6c94c0f40b2dba4cb6b53e43ceaf02d12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:98acb6a4b060c7997dc15f9c47929cb8c1f4a1802f2fbc9550852e58d270e5ea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:23891a369aa5312316e0caa3033b0625886f5f6153d1ff3947b20c4dc2bf3f14
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:d5ec77eadadf1acdb2063083961bb7887abba5425b574564b82c4d799d79304b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:e4e8856416d5c60eb312498144f79950a71fa5c5e71536458fee55d9aee4d78e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:6bf9a5d2b2f1f4bd9b5d0a67e37129a8b465db7b1aeefa21cf4f1526f8f8080b