Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.36.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips, 1.36-debian13-fips, 1.36-fips, 1.36.10-debian-fips, 1.36.10-debian13-fips, 1.36.10-fips

Index digest:

sha256:909d0ef6d104a107adb03c692b6521fa39bbdc6097270f0522f76b3eabd60191

Manifest digest:

sha256:140c6b9d6d5850262bae992b8bd87eac1a7669a94701e8b0c170691ec1fb8be9

Size

36.78 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Ends Oct 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.36-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.36-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:99bb2e02ce5e48b5875b3f95c90cf1d3f6ec1e4ab8fd0f1d843b0fea31788bbd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:1c5121e974ceb0c923c28b8394f42f765d287d28426e8d45fa82053ff04200f1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:7355ea37d5cdac4387547714f93917fa14fd1ac9a20d74302b60684491b44192
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:55cfb07d09da8a5cdfa2d41bcb00e6665eca26afce9137fddaaaef02955e980d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:0f79121c1dd0cd9124e98e8eb3c849ee7daf8c0d1fe27d693553e20d1c3bff8b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:30a87b186261c5ce15dd42e4949d1c837ea0481e3569f2c4770eb1df0cc44512
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:514dd246e03c9999dc0e49032deb8f1bad4efbd320a4c07aa54f333481c1a158
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:74b3cbb07405ae2a373d7a7daf419db5acc3c034a89b7a3e3be08c40ecfee1af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:7c6b7d0080eacceb490eed823cfd0bd276ff5711b6b0e3288c3d6d3a075db824
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:9bcc6d34f046ad2c9b4d96dcd973554b8ac7717191c6041db44e17b881958b53
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:4ad38a9d7f8d2f746c758c50c721e5e71a1313e79e08112705285ae5c6e5b714
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:0fe037bc878f1e5ebcbc953a29998f2a1ae0ec4f83185c420c8670e03a382d5f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:123abb6e8005ef74357f5aa440dc1c6318a42a576ab194ece2fe374f66c016a1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:0289c5ad2ab73e4b558bf4a1fc234c1f66276bcd1a28970f1e4dc705539bb0e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:d37983993bb07bc609c2e77fd88e8da3c5305dfafdd5462949aa604be3dd1aca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:e98b398e6d5940d159cbebc9e87c1648cfc195764a0b8462fb46acfd52687c03
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:a8dc45b38d8ae93c249021434945d5eccf8e437e52eb50f6db524a419e4159c5