Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.38-debian-dev, 1.38-debian13-dev, 1.38-dev, 1.38.4-debian-dev, 1.38.4-debian13-dev, 1.38.4-dev

Index digest:

sha256:4106b7adc64419da419595c25301b9ceadb2164571707a25ad6399ee53641b74

Manifest digest:

sha256:4b7a9b909609c00a4b596b2b8f52f9c1d35430de989c64248bb039d71a28caec

Size

56.02 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:dd1b71127525c992184a34bd08d435d7a629832fa8cb2ea6ee6ac0ce0ca97807
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:6aa234b2e43dc331eeb948724525dbfd46bd2080774395c619a3d760714dbd51
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:d79edec4c700ce806c3ac474df28177e02c5badc4539dbdbb770ac97597e6a53
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:ed7addad8c0978d60071fe22a1a24bf45e5553c1e0d88a66358e0911b39c7a16
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:2fd89964c40f5367e673629386024ee29011271115d4bcfb0df0c00d71b7f7b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:03a03b99f969f3d3765ca7a8d7a4d0800fd2a1d7762f02e0a46cf63a2f78bea2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:adb49a10632ba9cad436671cea8727003b4f8a711033444bc9a896ae893bf9a8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:8b6b445aa7a593dcdac7697ba19e4098e0188cc830df019c07b276023f2e3d53
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:1868b386461bb8a4a08bb2855e3af4ba39528d7500f7ae69b0e032359728cdb7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:a5db9101ed99cf664bea19db9fd83c597753ebdea644a5e229246d4de0686eeb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:c4b66ffcd4fdae025f2a2138b401a725a8832d6272d3a61da2cf4e30b4186aa8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:a452f10ff11826f0e6f94620f959a641bba641e83bd575230098a6c5f04362e5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:71dbbd572f9a35a4d46e3b87aecd25dada2e4a1f9b29bdb5bd2c0fd7bbe65517
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:9201de60fa37a9d085ad964820aa9955bf6827239c27c1f44c0038db1871d2ef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:14427e1835983db7d9f0e6da791ebb1c0cdf078cac871c27d3362c3643d0eb7f