Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x

CIS
linux/amd64
debian 13
Tags:

1.38, 1.38-debian, 1.38-debian13, 1.38.4, 1.38.4-debian, 1.38.4-debian13

Index digest:

sha256:129e7a464ea238e09aed81b10dab02424815a68181ceaf91a73e7aac95e0554b

Manifest digest:

sha256:bf988af37b2fe21181929812560013ffd20f3e58c7f6ec4a5287465cdbbc91b5

Size

36.84 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:d1d71d1845723c988b5a0e6256ecdaa67648cfd4fa16ca0d7f56bde2fda1cadb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:cd6140e66179b7b6f61a96b5c200a95f40fe27119f312ae4fd4fc9fdb07dd3f8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:f8952253882118e44418c7a6c88fc25a7ab5472cd6aa4d35186bb940df59a659
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:45f2b1affb031ae532c159fa68845b580f397417cd0d03611a5f3bbb9093d9f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:1ce6a33ad204d5275dcca9f0e9196c96258cc792a1a27724a389d6d5cf25c2c0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:575c2831af8d9b9323fbd433919862b20926ab32f06bd43429b1361c2bcbcb84
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:bbcc758c28d827a7fc0c1f588f67584d61cdc41b6405a7272bb8b75904fc7d27
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:10978638d1ba50a4cbf3986a03a72768c7dacce9b72694d7ef6e8574c8ed1a4b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:e6b915900e220458df978655d9aa7ad7bf1d8aae5bff903e38e60258ab7d3b62
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:656ef747582509e585c8fcef8e2299d212b057a98890766fb4e26842552d7ad7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:e479e041cae7ed13c1d7c13d621a3dae05f14af0ce7482e2d410d8fa3921ece1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:27e9b73142cfe1f1c97d4b8179cfe89b6e059ad0f3126076c0affdc5d123a95e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:d824f76b0b18a7eb973634872d56c7d94fb3196ec87bfb703ff2df952d16d435
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:73711d54a5f6b26f610e419e1d509a4a217934d01dddeaf5fc7fb13b33c0624d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:a4eee167e0defed22b4026a9211e26765ae0620221e424f0418ceb64e30e89d3