Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.38-debian-dev, 1.38-debian13-dev, 1.38-dev, 1.38.4-debian-dev, 1.38.4-debian13-dev, 1.38.4-dev

Index digest:

sha256:fda2c79816086bca4b1f7c390842eba9e06c9f647728f8de2041cff65934f565

Manifest digest:

sha256:cb281ac93fadd5e843f1a500dffb14e7009d6c22169ea1b0b44fbb11c86b1460

Size

56.02 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:323d08f7f2d773a086604767d3f3414678cd92a2a28a531e13611562d306e558
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:0e129cf64483554b3d6a94bc387ed6b9352a982a8cbfa7faad4a86ca1fb57e32
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:a4970e02f29cfd2ff4034fe5f1a85bf024ca5aaa3e7a358f05d4fc47ba19a6ba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:09e7857c677b6c4267a99d0bc2193ea494a4ab86454275951ebba5cf02f6b843
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:664852a6558845cd34e10d2077d282bc0e02a97e3db8f192a802e2ef1cbf34dd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:2bed4f3c327d49940b6eea0698691e6e6e4c84f002a947bd75f03e24b0072e49
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:8f41f57dfa13d465ce612f4c4371acabd91f8a52fd6810a90b7d6e83f92d5c67
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:bce5e4c8688575a6958212d5234fe6ae271883252122275344574dec5954660c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:0e871c6ac9e6fc8ff0992b1fe7e455387d6968646c67758566eaa92767c6fbf8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:6ed9a16316b26f2dc873cdef9e2be2879d1ea915b18e6d31196ad7441af301f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:d188899e067200b00480d5bc5a591ca6c9a790b2bcd10f0476bfe50e4432e4eb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:6f29cb3dc13c70667dbe491b4907c5d732a9fce45346918cce1308877f92a212
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:ad88d7cc19586d24953acd184685723a0fdd72da561d2d3faa49f37420ee8250
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:49af1e4f5883040feed83dcfcddf6ea3f93178fe5344c5d8c1c06ff83f62eb27
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:1d1842b2044a3e6eb7c377aac126cea5eaa1650c52fa2e47f065862e77212ed4