Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.37-debian-fips, 1.37-debian13-fips, 1.37-fips, 1.37.6-debian-fips, 1.37.6-debian13-fips, 1.37.6-fips

Index digest:

sha256:cab3961f940010757688cbc303f0d8931305cb2ed4ff8f487eddf4e774cfbec8

Manifest digest:

sha256:6dbb1a4685c3bb1c9851c94411345178692c25fed2b0a532c11a56be97d7d71a

Size

38.38 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:f15ba571b5200ab99ecf8286ea82e0268aefe4e711761d3094321cda0ac31f53
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:881c18314c1e37b78682b77d7f93caccc35c74c274c55b8ea3a2abba5cf311bf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:30762fb25271a4d65c2982cac80033b2726fdbf4efeb714bb3928cbe295adaec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:445c7862565f6b0cb0c83967a4e362761d3c8fb9e568f8b2a422658344022222
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:10c210de69d073d0de174a03a3a0e9470ad053d9d5857c65df053c4a643e38e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:0572912c0ddd6c0009c79273d5b991f729fe09c9d4e21a308614a2de9ebcd981
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:576ab19b5a4d22455773b61de35e16558d742ba464243d8f977dffb6ebaebba5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:b3e425ec978e261d970458d5024e8305b9f0d8b0f9ececcd9c02a08b9cac46c8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:5dc1a6683a4136b82634590b3d183377f516b2bc3acd014365dc37bb0081c5e8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:53bebd41bd6301cd42fa98000235d16d40fa38962987f4b48e4e15c2603a4d52
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:3e52a8461edbde02abd531d2ce89d9da75fb157e42a7cc5065e45b5cf36361e3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:639175f598e58d872004d9d45243d705a4f2f86f06767968a87b5bfe37bb1d09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:08f13d5b91a61a9dc96ea3365526b3814b2ff6ec84b3a9e8286704d69c6ba5c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:4d1f721f705bae93562d3c42bec2ff6d8f57cf4925d254e6562005eb244e2c56
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:26d893a9abfc17a12d738435a9d62447e2f9b970a7231248346552ce3c6e2dc5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:67b56546f16c616d32b19d9a3e968d1fd4de7dd66756043eabf68c192b235d0e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:a386477c20b4489fc96a956b87265dca1b3b48b86e44d15d82a3add4010c5daf