Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x

CIS
linux/amd64
debian 13
Tags:

1.38, 1.38-debian, 1.38-debian13, 1.38.4, 1.38.4-debian, 1.38.4-debian13

Index digest:

sha256:6cb52ccd469f609b57852c266932a07d44e3f9f62cbb11b830067a1a87c501ab

Manifest digest:

sha256:de251895a1933c628c60a2e0261e1f5c31f6492bc1a8b4d0c2864c564a980871

Size

36.84 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:aa2fb6d81d168025cf09f0c157f8d95327de68c4854d65e7ed3a01f169ebe003
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:8ebf9fa4a449dd3745a3e2a2a0f3a78986e7e51a1ff50661a134a783f78eb13f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:50a6feafb3037c1724878a80d77853d4a8a0695f9d9612fd4d326b557e49294f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:76669e59d8447f251e83fdd281fa5635a8beba104e8845426e94cc66560e3939
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:f392916f58f0182033a34ddac625c5fbadba45b543e5367cd6bf4544be35f927
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:5808f45525c5e13c57277751726995d28bbe630bb6df88c44d289aac8da52eee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:1381e0accc7ddc6a640d7f5855a8ffa45e387876b03a139f46a1fabcb7f5d86f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:498d439eac4fe6f64d13f87c58e19cbd92ab65923b5877564bc93304e163decc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:7089a140463555b896ebf1a6310dfa245a1557cf174dc92872bd90944abe85f3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:d015c9a6b4f7caf4d98311baeba20a121c831d2755e7cf8640b651fa6f83de7f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:f8a5e2aa2aca20c95c9029daf032bc64cc4234fd3b616e1eadd9d063d0a702d5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:47377b16ae58b5fd10319ff34b6aa9890b0434c5430e70718da67473da3f24dd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:8679e3d9d82e66ede1099406a34e03526fa5754d4285ddb78b19ba7aca55193c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:70a17a05f60627a6d57f6a7e2beb4557cc123be3877af690fe91fc7d3dc52829
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:bff1c1ff0aa8db7e1c42ec9b1c6cbf0feea998614af52a07267fdf8b99e69ed0