Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x

CIS
linux/amd64
debian 13
Tags:

1.8, 1.8-debian, 1.8-debian13, 1.8.4, 1.8.4-debian, 1.8.4-debian13

Index digest:

sha256:71b6caa90304339fcaed0fae1e90e7d894ca43179d10aa965eeaaf8f722159a4

Manifest digest:

sha256:d77794501fed934b0389e48bcf76f5e980a46d7d30107108d49b8d70a0ec5da5

Size

27.56 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:4c6ec61b67b2b3ad9d0bcac762851e6e909f3085573b36f154971e82c1318b62
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:958a9fe722a5cf673af35fd761256d9622e117fae176fcb96cae9c600c194dcb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:55e26e3d494ce1647c874ab7bc41621902afdfe729ba9da2b6be53a253bde5ac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:f876db542fb920ca052ceca2173e1e3c06a1fd9f0413c24b86f01c95a039d5f7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:4d671ec58cb07d87c5deda97f3e7c2c23095b728b757af3169bca0fac7b20c46
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:f6b125a0916bda57ef8cbd1faa7fa1b0dd957323571bac3f599f4910d141b0e6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:a75eaafe82cbb5955b696ae392ddd2064b7e5ed6d08222f9260aed3852c0fc22
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:33b1d38e1679a4ebae5e7d87872efbf1cfea1ee3b9805e582b94ae2f6958636f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:bd4c0d4d2ac3a61750473efd14128cc4e52c346388760cd4d1e26bc92db43a82
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:c4b3d12c82b8e04169bfbd80bd23615c8a364e8e060e4d573ab4f426f14e0a0f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:3f9afb0c69e7be1fdc6b2462de05711edbd3a16d1cee9def42b6fd9f7ef73fc5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:dd0666c68ab236715c4b2c7a86fded65b4bfc580dc1a7faf002bb5272058bcc4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:288bd83ae40238cfe16f0b1f29b29dfb84c1bfe4ba6a695cf70b5cbc0b10ddc2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:efbe9361230d5b7a992a275283f56e2a39ffe008d56f1d5863fffd1a984ae3c9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:4a4c328135bdf7007257c9ac8771e9c536dace273cf3cad1256582209d1ec8e1