Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.38-debian-dev, 1.38-debian13-dev, 1.38-dev, 1.38.4-debian-dev, 1.38.4-debian13-dev, 1.38.4-dev

Index digest:

sha256:1eb743a2b662ed8adc9200a24b03c02f9b5dad2538debe80fa5f337d670ab6fb

Manifest digest:

sha256:a6433bd564824b79c70f3f1f4ad487412e89848ceb66140d368c58b2c36c21b7

Size

56.02 MB

Last pushed

55 minutes ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:84543443cc60f73806868e2d1316cc9282c91829c1f9ff5f215f571125ac9e6b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:fcfb25985de9404022e55e5e822fcc3ed61e126866f6456857ccbf5c29fbebb1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:6e2da1e4ac56b0f5a5be4c8ecbc61899b564385fbe1e86abad398ee8bf591f50
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:49a55ee24065fe5f9511241082d223dd3461bd8b2b9cdd409f6f208eea6f2458
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:3443b528010cadee9b98a7a28cc1998cb926a3a9cce5dffecb8fb957b336eace
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:bcc2e6a2cbc6b9443721c8bc15a25854ee6aefa3c83ee8ff7d538422d5c8a2b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:6db945ffb0c82efcbb8918bb43eedfadea6383123004971d037cdc18e8d71015
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:c8d0b9ae5382a59d238fc34192fb05936934d395b537447d9447856ccf110a3a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:f74ff074795b1cddb0529453c7b0759091ebfdcd68030d445c7f2f1a8b95bd9d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:7f365603d12b2b540ea075311ccf282e53b609e62a6e45b71d798d26a10e8e9a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:159c0f86dccbcf960bfd2ec658dfac30d2ab5837c1c2e738e6c70e8a2b7ba4cb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:53d2308b6f75eb187426438ff87945d5efb55304e1ac950fe8df4fa4d4c288d5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:ed767678eb8fae3de24e99ab8992aeb25fa9e72607c26ab12cfd1798d917c842
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:777fb81a74dcf4339e7417a23ba75d85f6c25e097c411b21d765a2fa1d471e97
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:20085c0270b2a918d8b49a72e5d2018e8e37c4cb00a18128655b1891024ef7cf