Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.36.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips-dev, 1.36-debian13-fips-dev, 1.36-fips-dev, 1.36.10-debian-fips-dev, 1.36.10-debian13-fips-dev, 1.36.10-fips-dev

Index digest:

sha256:ec8b391cabdfbe01afd25ce88f983031d1594b25008af177ae33b9a581941df4

Manifest digest:

sha256:711e84189dba2e7b3ffcbe8acc5da8bb1ac86d4d024ae661efbea3585fd7f066

Size

51.82 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Oct 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.36-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:ea83d358326930264baeab380526e04e4df19c73ae18d064fe3f147d68db2b10
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:4e504b5cd0d9d57e7c5288b64966f160b0fc7180228f716fcb81b0cd7573b8b2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:4c05274a397489bd372ec7c40870a189f1055ac860ef4bd559f9a3fe7096dbaf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:0aa16a936b7d30f7e4f82d82b2efb1d59c89e3de35071c563ebe08c172b2c9ca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:6a164c6b55c6f2bc390bf6ec34a7569a8690919409f9e6401ba318f92e983166
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:0c41e743a4a30f0dadd1dcd84eb437b6ad867b28c80ead0a36ab4f6d19175309
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:a40c7d1c1e90d4f5ef261b78f895e4ce7ab8a38e674e33306097bed6ffd8fa87
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:298ebbdbb4717b29930ae2b79feea024a6257111861e6e7e0dc8713e904c99da
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:b7663e0c559dfdc8bacb0963866203f0ad6ad00e36415f7592971627aead0368
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:e236011559211323a933babeacdf69c5daa5dcd2e512f4b76447c29f157c49ee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:f9ce40c9624a4f8ee686578e2d54376e4035ab730775825a3bef489e1110e4e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:fc0c5a625b15b43abfeb89c8466e5c89131685e1c6fce4207a7151c967f81019
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:6bfe4a80a01e3a0d5e2101a827fb68e44db797a21fb4f02703dbabeb6c8bde2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:5f8d21b8d65556da151a27b2daeb2d99fb10c9f812d51121e1da762f3397325e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:f542eb8951eac434627c83dfa9d1b39e9bb8fbd1b94fe6a3f8b4bf7bbd4579f8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:2ec6de3f588f544494fa35b1e8eed780c19428a8eb40eed727a51a2912bdcd18
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:81b68301a6126e0b78999e8b9e41a2e15c47b570fe7c8bfd1cd47163bf0aaff1