Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.37-debian-dev, 1.37-debian13-dev, 1.37-dev, 1.37.6-debian-dev, 1.37.6-debian13-dev, 1.37.6-dev

Index digest:

sha256:8e4ff6d264e2c57682651de64eaa249d7ce237a1972b18586fb0c38de9b0b9d5

Manifest digest:

sha256:512967e3008dc1d5fb24505eb5ff972761043c81559e0907ab5965aec731d825

Size

52.36 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:d848d2ac4f98f372a838259cd42e953afdfa8cf28c18ba876734edd51ae8a996
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:d5de4ad8da471ea8b4f7ddcebb0fbbba2a0fcc734ad7ac4459ba546472c5f6c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:2e2deeacfce47c0c6c7b452328242463910f825d1fda31e9c8185a4697ed81f5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:c67ad9916ce35cc6c8ae9aa956eb39af3fc3a0972246e191483cbab8e464a593
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:c43625915dfd0600f2fc30e15794c48291ce443a1255e104074efd4f2e2a531d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:5ee4ef6195767f6a2ea66385152567f08ab0956e07f9d0fad034fcbbb3b1dc46
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:6ad2faa87f6370e6d3485303bd0b092c7603536a05d7980916966baae198afca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:446e8b2a38b0fc031f268bd36857e19577caa87f849b5cf3e66676a03ff149cf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:c6f333e6c7a7aaae0cf9578355f0b674981bab6a9ef21966e0e4f00439a1859b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:428e2a0c82f48b7d1f90f9a15b935b2d0a7e4d89b103f43bcfad9c72cb3d3e1b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:dbfd0c496f95bff68de5b002f4c6bc82b2b10b286c8826e8f53d1dec0cf03a86
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:87eb6dd4568b57bd8bf05f2c17062c00138b2a5fe89b2551933d5c849ade7e0e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:ef2c88545ad45b201a2616646eca51e72f74c30326d4aca713fb3bc59e0f5956
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:afc47e94cb0f20404b26dbcbcc3130c530012891b832b2b8f19968d97a4b84be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:108d15ceae6a38bc27c622ebdea45fbb16da442392ca1313a90d0859205246a7