Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.37-debian-fips-dev, 1.37-debian13-fips-dev, 1.37-fips-dev, 1.37.6-debian-fips-dev, 1.37.6-debian13-fips-dev, 1.37.6-fips-dev

Index digest:

sha256:47647c83b2bc43111e0bc798845feb5a67044b0e47ba353daf26d4409737a790

Manifest digest:

sha256:3325b8c458dc9d978c112eb91e97f6d483b2bd62fa662ae9145f72aba16e214c

Size

53.42 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:e9a355d3a0368a3fecc96f07172f2c298e6fce09af8d6c4b694c6c791b1d3297
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:7e990bd0ac79a476dd31da6d25539735cc3fe70b9972d8bf6840de6570aae9a9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:085b7d53ba728f5092aa07aea9a26abe09bbc28af85e332e9c688fdf1f59a812
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:b42e1881577333c518aff87d9efe06dca17025319f1e87f9ea962ede9250e098
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:6ceb2a38135a0afcebb1ec0f1ba8dfd204b23d0fc48d496fa57dcfc9b1095d35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:d836ef6848e677621cc72c6d3646900054d4a01481409e58f55a038e05c0a019
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:6fd3e60a0089f48ba48a11449a5b973d8033f9380fd56086ef39aeddf906a892
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:697fe497d9e0983fa35f17684f63921b33a6180005827c900e30e456f1819e12
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:75e296fc9ba70460fe96d3f4bd8d5614c51ab5db88bc5bcb2987bc1321dd6695
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:15b64d88c9faaeea66958b690aa12d81967773b568f5d652d508616290a882ed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:b9f78136abb3e0f9c20df2b4e2dfd583e44d0d310455f91265079e088c5ec480
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:698c00c137cbf4a0107b8023dc9c380fc4d3ba9fd6a372345383ac8e7bb10cb1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:766eac0eb5a317eff6c782e3afde16358273b41d3ad6aa693d44036c8f7c7bea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:aaf80eb686a2759d12feaf674756419c046ee468afdae01a0cdc675c8f2d929b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:1734357a15c29642b77c9e07c898915040745e6b4b232221632727bfbf7d9aa6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:9eae139ea7817e5d9480a09cf93db48cc25bf8cd0558d388bed62e4a63716148
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:9c216d1dbf653dc35ff09aeac2b7ba8be046eaa71b97f009cf0fee61af75e1ba