Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.38-debian-fips-dev, 1.38-debian13-fips-dev, 1.38-fips-dev, 1.38.4-debian-fips-dev, 1.38.4-debian13-fips-dev, 1.38.4-fips-dev

Index digest:

sha256:6ae99956e1573799a5415504436c5d140381311557aa52ecf144116e81964e33

Manifest digest:

sha256:db524d55ab8c095d9fa86e71d1d42c427739c17513a6cff936bfe20cca643d6f

Size

57.23 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:8beab55cda281a2b2eb2810c95f7c857c2961eacecebb825c2bcb45f39e95e84
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:6647096f7f69170d4001518192c5c30f8d2f62aaabf344898c2604e6ea951fc1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:c330758ebd680322f7516b5903f419757de2b94092696bc001a46cf50d4c2cb7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:7f62140b28d8e072f896221fbbf010497b3a5c7832a1797313d663aef41be8a1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:8856628ab2d0106b51927b37695130ef6e1a3acdd725f53e40c3d0b9fb4d7f55
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:dc67139400918924465b2e2911dc591342348f5d2560d58294caf7180b63955e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:92c903c5406254b4c1c783619f4e58089bc07c6a7db622f2a4b2625d9ad6bef6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:7ea1208d33cae6d0f1bb3df71439919ce21897266e73ce7bd83f5bdb7df47cba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:2660524062902f58db6e44b8b631cecf010eec5b88044ba988ca574bb8fd3de5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:4dacb7444921e43d58675fe0387e60431bcc1abbfb0740c6d4c43dec1cdc5242
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:a335a4e49357b53bf42a9646c60d97349ba6d7d4c7910caeae10840f14ccad31
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:b2d5e265022e2cb7b3e7e0871dd4fe9ad0875cd82fab001c3af0fd7b6963688b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:a57f616c7de44f1febb7c42dea8add19f562fc3531d7d1e5d1001bae86b31c9f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:e97bb2ce66a43b6a2f3dd26d8d63a284896483542045954c7f752ee7eaa7749e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:d3a0e79688cf5a1f425658421adab9e434501126e760dc7d1bc9d42c18b9f97c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:3d11c573d2e67cce144d86dcd3597497116a73544878e2c1d7c2c2388e8838c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:19177191fbc7e13cf23356099e4dd694fe726de9cb5e38ee05182a0925f13e80