Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.8-debian-fips, 1.8-debian13-fips, 1.8-fips, 1.8.4-debian-fips, 1.8.4-debian13-fips, 1.8.4-fips

Index digest:

sha256:474b04d96ed205f5fc13c9ea33d516f7c43c64d8d822b753cf9ad233384aebe1

Manifest digest:

sha256:38cf0e6dcdafef431458cbe2de126f9a6372155877addd4eadbc8d4a97193753

Size

35.67 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:a83b1a3aa9891144fcaf7d8962ac55484e2e488d0a4e41a2e49c99e7fda97b7e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:c8b869571fba15b34e783bbf4504735d87da542bb17bfc2f118779abc7e63a90
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:1dd66cb41c22fddbfe2b673df825461d7608f2305cf713b929b37ea5e86b04c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:f5dfb8c28773c5bda42f44e79b0a4815551ca7a9dcbb41d0d5b721ebc9c60f2f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:687c9ba5d43ee1a5f5e1553a0c138692162a8719065bdee98d47ee2d9f92455e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:2eb1a8cfacae861b685ffd1a1ec7eb93f423e3f0acaa5db4a27a5351ce396120
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:65456e93eafc02af1c453119f0bb1ab66cc3b89785dab65d20d7f279b6ec00a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:b340744853e6658f627ad7c7eed122e53f8519d8b80ab807ac3b6e6be1a2d2b3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:a96bdedf3a79a1aa40afce61dceb6b8b91a1d008eab104a875f4e10486874e98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:f78084cb6edff6adcf48424ed74090662561168fe18fcd271aa13af9053df3ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:f14c8a1744b7b36efb8d4de7bf7bb9645338f91887f16ac9c0528b35dd465773
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:5eeb61a0ebf0fb97af09ecd0e865f17fd74b48d31509a43bf101883584c33138
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:7263a0a810aa8de7f829b74633d16f0e06b9b540729c569b610dc8189a5fffe4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:3b9c4b3e8f74901ec259e22a0b6d8d6dbc4061592592c97b4df6262a804e4549
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:527630ec7eaadf8c7d2555b2735861a31449daac0fec29ab51536ca5b00a3cd9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:95c07ec53c33a699b2d1ff295fe3b48714e54ebf9001d849d93baf2ba581c405
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:524cf87b2a91dc5bdc6e398633441cd04ba812328b8788d3282b98319fe33e34