Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.39-debian-fips, 1.39-debian13-fips, 1.39-fips, 1.39.1-debian-fips, 1.39.1-debian13-fips, 1.39.1-fips

Index digest:

sha256:507b4cfb4abe5c1eee5387295a6b85e595b477805efe1132674b81fa2958a24a

Manifest digest:

sha256:b5419e8400a1d16a083a16b68f8fc89c88e12d40f8096b2b21aa3a07f0accfde

Size

43.21 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:99bf7fa5939a78929bbb4472c9acd66a46201f6343c1ff49a9b2c17cc90d9af6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:4234e8efc1df0ff02fc2eed038f04f8e9f635baa529f651a5d0fb678040144f9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:acd0f59b41294f1ffdb62db44a9363b95187b01d06ffde516d33844392300b9b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:6035e212b9951aa375f2813ef3f458538d9ea79cb07bd24020be7932cc2fa48c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:5ffc45033d63fbe14172613ec0a301e41913fb77e8e3d2722fcdcba713132bd7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:46f0b26c1639016247bcc8a47e8821243aa477ec3c7ff08cd93c04fdfa972e1c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:459226683666736a086ad961cfd3b89448b7a30e2a6564e3b17ea803199820ca
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:984177341efe59baaf1dbf49c4c94cec7279b5c84a1c2bbfa58a5e325e051cc7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:f6d89c5eadc4ca5216f472937ace9a4d8d9097e7643d6de35f099ab8c928fa00
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:dd4f764c7b01858ebf4b94836bb974a60ff6cdb08f7b4b8cb63f0eaeb3debf05
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:8ae16ba38620a360a06a6a712a12854084561d9786a6e39d3fe01c7e4de633e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:6ed89e48fe30716c65ffb95b787c24e61aca520e42395633e29387e13f023ba1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:9d688221eb0186267ca9494e634d31da52c0408f4e60ff7891d9422932021b99
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:3fce73a6c33417442a5500b7660284e78175a7915d9d8db88a9889e3fbd08771
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:2d64f4337ef27bcc543de099cc9f83ad301ac3582915873f7fccded96885393f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:26340e22abbad844c4ce14a177d6e0199895fa3a9f4c59c5ff5b701fa0e5d423
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:4baab9eacbfd6b50011f87bc4dd1e63ed63050e210cdcd9e49c5a64b92f18fa8