Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.9-debian-fips, 1.9-debian13-fips, 1.9-fips, 1.9.1-debian-fips, 1.9.1-debian13-fips, 1.9.1-fips

Index digest:

sha256:d73c9165628aada67a557ad0ca4449379f067fb3194db41de34eb5b7d45a065b

Manifest digest:

sha256:79a8547d7f5b634acfb56c1e352c2f0d2e6808d4278eb12b472a33c3719cb520

Size

36.02 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:8d99cdd30b51025d9abdd8042035fd2a788054bc371a7f559d01956e04808d16
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:c769660b2b50a7cf88db4289ebc44b7d8aa8f27fd3743faaa3fd8e795e152c91
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:c5a7f89b5f669aed0c4601e7064b35be304fbbba82353ec041c7388f879575d0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:636ec6844ecd503540dc98ce7b013ebe2e804d43c1e388f4e7034625f7c6531c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:81537488519f2fd29b60e5a39ba13e8b89fb3098f952bbeb911304858c1d8655
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:2a5e0d24461f84603a5f37d45f1cec2358c960e3a6d3f5d55f2b82f495d8e893
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:a3d66d122c51369164a1464e9e8666263be442f54f5dc440582ae2153fad5bf2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:0dae9053195f6e494415cd68112608c576545f524c6e0f7f9b366642d2ef7cc1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:e7d373db53de88b33c70de64e932c47bf4f215f5b1400f8d1484699f288138da
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:2d1edc453a0c3683a17634b96523cad51afb6c588abc138d33918c0dc1f21f0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:626eb511b191df0148545a3c5e954b61fe8590624432b4fd33fd4c62409d4231
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:1f68edc23d92cb69cd8b4b4efb25b6e5a9c1987f6c01e95601074fb4cbe384ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:264f873d1bfbcea408152cdc3aee5e6ca393337e6ced933177cd073e45525ced
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:182f790052d2b6729a24bb3ca9bcf372a4c5464aafb919871e59fe97083fcd62
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:8bc940e5f3ce2be3ce0d0c50531f56846fdce263b70b6f5291d5370e93cf3cfd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:8e918e6252c1c1e4e2be1662eca6e235f8219062a0b9e2e665640fe8d1eb309c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:c5ea83154171d132e394c8f7cc1022b1faf36243e85054ce64f143204d90d69d