Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x

CIS
linux/amd64
debian 13
Tags:

1.37, 1.37-debian, 1.37-debian13, 1.37.6, 1.37.6-debian, 1.37.6-debian13

Index digest:

sha256:904c6c156c22a8c6cb987108d00b919dacf308cdc6c1db040d8c68866ce01bc4

Manifest digest:

sha256:15a8d08ceb676992ffd67fb88d85299c4cf004eadac122710d8eee257ffa2704

Size

33.19 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:3ef6474895fe9bf49bf7336fb01fcde0eb55d965eec210949a78f85f6fe753aa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:ccf710789926b6f0a5ff15435eb6a1334deccdcf9acc54c6a916420ce78c31be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:c25e8bddb43651f4b2aa0410b9c23f87d466898cb7c3f94e67423c5a0abb016c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:6686d5d13217e3c85a315b970b8d6dd12e42af91f862c3d34205899c23c9bce4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:6d651e70be4e61dc6edbd065a5f7d1b90bc73ab711adc1c79cb29782497896fb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:d3b81ca20ce4abef4221fbf9f59991099379ba623db9dfe9eb6a3f1b6964d9ce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:f71c28a6627f60b084d99ed7c26961e582d5c7414fe6759304909b521f9c9bc7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:54558602433bbc7f41cfc581f38a20290a791caf480ec6c80ad550f4eb8c570b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:7f6846a7de1d60f72a013b4602605ab4ff011c41972cc6941f17717a8951b5be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:9734a546c3743e2bb48b31f258de6da2addbca7d5def47aa97fdd1b0bc0b43f9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:898867ec4de0f12dac9c5e8f997c6aba70c65c4b643247c415896b9b9371a7c3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:06a9d0847d72f8a9a081e53fc17f43596b9fdfd58fe71422c7fc59fdd21f1933
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:2d6455e4be6b3d852386310c856e0f513fe08f4dda9129168f00cc3f5c4e4b86
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:a4e57178c7ad78be818f10c7262d9f97ab3eb363e1b0b5e276a7e7fcc1c73780
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:474096c78283511c34be531eb5a91eb9f1078302631d75af68d434fe9c0c683e