Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.1-debian-dev, 1.39.1-debian13-dev, 1.39.1-dev

Index digest:

sha256:d1e74bfd18fe9c18a78dc1e92dc45203368ee41b1e272d1fdb63d5ae288cc371

Manifest digest:

sha256:224210fba478548d1c6d820394412f1d973c2a67fe886a22400d717702215dad

Size

57.06 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:f8607955d57077c5a118ba1c61010cf16ec2ad42c86034b4b98fbca4e74bd070
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:46bcf06e65f901cdfe9ba7747d6171538935c13e3804b498d7e85f52c68bb0d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:aa00ef4090dbb64024bc08e167b5b28bde7292ef393fb718c473d705194c2766
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:bd9cfcbb8614a093119f99927431d2b0b2184f11ac9dbad8aaff0d74b74e35fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:0806373563c3213f246ea719d634f39d464912f72f1fa3914a8f31e6d5503edd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:cd4997cb2990b6e7b5dae88aac8f7b09895958c535afd91e6012b66c8c7ec74d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:672866368dd2ed4ed52106475d5c92256c5b4e76d9d8e0f1d6dbf93af8220033
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:67029989c94b7b4f2334866e1c19f49bb9c159eb7ce995114007063d4a6d1149
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:4d5449fa6b08cc08dca19144670b9da709723f8c2fc72467719c7fd625a81402
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:a3f661d9263ec644c8ca950c25fd9265a0ca34cb1dd9f011eddea0db5464e806
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:3dd74edd9b73b1f6f2da0a445d1194c5958e1a0798b39f5fb955532ee6f008ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:8be361942fd884f15dd3ccd6ba565618a2c562f28bd459b9ba6a90fe4d5ef9d2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:f1e02ea1abffb59f34e5c03fa30a0b3708569303d351dac410a1ca713e8778b9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:c62efd01dfb1573388007f2b7111c26ddbc72a35be67d3a02616310ddcc19752
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:3a11fc20a5a7a282db25e243a206eec26211d9c990e0086ff937a0697891d8b2