Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.36.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.36-debian-dev, 1.36-debian13-dev, 1.36-dev, 1.36.10-debian-dev, 1.36.10-debian13-dev, 1.36.10-dev

Index digest:

sha256:f2022df6c44ffa41d379f73169d6f4975b3a968c791bb31142465c276ec884a8

Manifest digest:

sha256:3dbdff582b1364522873c435524bfd8e269265bfb5dd7b68cba32c02824da121

Size

50.79 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Oct 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:1eefb1e704ae798dfaa78c96c3fed3aa9929a89d231d1a32ff62457ee1ba091d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:d64befc933f3a2ff60231d7f2309a069e90f2a1d08fcfcec3a7aee8f01947f54
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:478bcf70dd7f5c083e51ac3438734c74b007d25ed9de97ff1312b2c314cd6f28
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:b060a771406d7feb2aed5c2652f1767060fc9f816041c23f5d9f43173ef59ec8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:992f4b8d4f0b0e6cd9f95315c87186b69488477b183ed71cf8f68946eb94312e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:78474beba6d9e03803f2a8cd4b58026f529c5b8bbd6f44e48e11ebc46cd00371
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:07f0d81d01652460e461754b6facdab12bcf66819a00637651aff414b208ae86
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:f1355f3c60f60cc3ec9732569c8fc6b95813e67bcf18ed936be86faad6354c20
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:0f2da597546113c089fc456f4c176b883c3a0478b78ab447f9f087349fceffc0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:abc972be6f4878a61947f8b8716614870933037cd5880f7d95e56f22ad067233
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:4210096d28b66dfdd149193efeead0fe7bab491ca7c7471437b1e92e0977cf08
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:7ff5152082ae752dad1da9e23f2facc904d7a23eb77392cdfaf18de2b821e4cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:2b1461d5d1a5fd14a1a3fe48262dfd19e19711245f52e2185401806ce4525234
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:a98107a19ce81c0cf2d2f634cb8514b8d7e7e00da3303d1e2ad9e87f31d5203c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:36d1efe2c4f9fe14098ebf3f8692b2d5cffa54279e5096adac3e7048857dd0b8