Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.37-debian-dev, 1.37-debian13-dev, 1.37-dev, 1.37.6-debian-dev, 1.37.6-debian13-dev, 1.37.6-dev

Index digest:

sha256:4b2b4a66e6b016b45aa71020e09cee118bc61b86d9cfc902ee555f6a9a547a29

Manifest digest:

sha256:50bfa3721da9dbf4922e61834744a5207ee2732adcb90b45ceb03bce3e008f79

Size

52.36 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
2
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:4c85a141aa1a68dba843ae7a7a819b82a8488f51d7f1fcf08000f806b62bb9d3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:91591f52817a05b5bc7776e3f2d01dbf91b8242085f5b4075799de8452134efb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:c668478d4a8eaa78d9ae1a77806973b20762c80000572c59e99498b3b6889400
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:98eb3d91b2e815eaa6bef2923a9052eb748ed27eeb62d2168b9615788457e9e5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:12a18f244cb5a93d6c031bb0cb968450c80c8a2c5755c8e570f65b0ef6901d38
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:ff7e78bdbbd75432ae21bfd282e5748ea933262bff13bd6872da97bdea558c97
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:e8623b86496be1d85d3bb70d7319b7a09d4b220d213308bbd0258c4aa36e0e13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:a2c6cfce32e87d597fea818733f5721539fed6b96cf2a4f3623142998341b3e5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:4271e3896deeac62407e2e18db7449ed3d5b636770efb6ec91ad1038c6277b5a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:743f4589b045f3de3730274a36e36b48f37d1ed41a804752c6bb2d727b315896
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:efb70ebeef9b2ce957807a48082f811e5d1f628cbbedeaa971b5950a4a371697
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:5c31513e9ff2c6a39da9efc94a433e7a883c4167b75b42e2cb81ae27a3e0b6ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:3f9c77ce4b35cd720b7998ee8263fb9b272c6f9c8b4518178ab9b7170bd91542
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:9742398fa6fb9d8ee7c3a3d68fe8325afa8473a9f264d554586661fb14feea61
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:6f89df9b037bae09b0a6693f54988477552ca45b5e35e5450ea201025d6fa092