Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.39-debian-fips-dev, 1.39-debian13-fips-dev, 1.39-fips-dev, 1.39.1-debian-fips-dev, 1.39.1-debian13-fips-dev, 1.39.1-fips-dev

Index digest:

sha256:8c3e3950f30063338f63a889a6697b9676e1118a3f4a04fd72744e94fff27544

Manifest digest:

sha256:4e7e67f415941b68a338f217fdedd77daaf06eaad6df46b602451e043266b91b

Size

58.24 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:7e55bc48dc9abca1f8ca16b6f95eb0305ac490cc2af46f4ccfe5663755736058
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:ab2fae0e4337414abaab6911984aaa6c8441cbd88767512a7eaca411b591f6a4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:2f371d1f0054c772b66a83611b5647900c8f89e8ce4e45af2bf3fc445476cec0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:7c94c356e924b5296bc60862296a7eacbbc956eb3656eabb27bc11c9cc571b3a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:15aeb6d9d650224b2b3001872ea5315aa8fd49fc724d36a86e72f84051f15b75
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:fcdab22de0513026ac4141aba7a9bda11785d474550d59451c97ff3ac868e249
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:22133b4e855189f808ccb7823b57152a526689caa18f922a2df4830b0ba303c2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:40e9bfe4f804c89d425bdfa151dd1873b23fd49861934e5b521b1ab1512232a0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:a97b77bd7d7c71dd14fe5af88860b9cf45fecb8e4d5352306d3b8796e9c0bdc0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:24d069fbca67d0f1f85872e349a19f7f557c0f6f2371d05ece2c3e21f60668b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:318efceed45c6b9eb76ab97adb62ee8f8c4b15c5c390e0508fafd83c7b7dd2ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:79cd38085e9a208c878b4cc2b560bd63b5843c365da894cdaad00f4f906f0e20
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:9b525aeb7ce9ce3bd97f5289cef3ac35e399108ab62893ccf29a0e64e58c9b5b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:be166691b02027f71e86a0a6097740f1240494e96c1c606bcb3f8bec1313c092
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:5b9439f7bd6a830c00eb811f79258496d6836bdfd9cec23fef315e2668d57e41
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:e231ac5e16629b0f4385f3d1b251c0915482ef38d362373a6b7d238317265f3c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:95deedcc0946003362b62f859e6c2e4da6b8cbf4be24c09682206bfda015712e