Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.2-debian-dev, 1.39.2-debian13-dev, 1.39.2-dev

Index digest:

sha256:d136b72c970815c8a351cea01cba203914d6fc66dee33b6631121c8be337eb20

Manifest digest:

sha256:0e0b6bee66aaea9d17be32c0f57676f845d49ec736d57298915f07b65d3420d8

Size

74.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:ab0b4243156a1934b9052d561a3a0a10e1ab4d27aa936491817fc02c36c3d79c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:143d5f8a7c6c7327b8ab2bbc54d0f33bcb6e648ff87c20dcdb2f055728d5519e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:b0c0718f61c9d269046f631c387b78c5403cef4b3895b8d516a4be296c837051
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:0e95993a1bf4ade7f31b925c0abd57ce00718c9be69e4e5b0901ce439df055a0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:90201eeb6ff0d75a85d014c67b016f7d254b15e87c7e9e9db8d27dbec9a8d65e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:ac1be7e79b3189da0ba67cefcaae705d56a4ddb5ecd779a1424826b4a9e83c06
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:92e7c47234836bcec93136d8271249069d2fe025c0975cc63aaae7da57203387
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:d2b7f3b2ef279bb1610e2beae63a47e731261160f862c7e27844a972f559f95f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:d8ef8d42d2a75906ab88d640fedc7decdec2015762d5e998656868cf2b38f87b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:d7e16234485d7980840d7113f2482a063aeff0b98d6a524d5cf5554a3070beb5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:7f9fb5fde014f84665e12fabb58b57394be48dc3b702e4502489c3a646a45b20
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:179e08d3dde867ec02d2e3619c37f12e0cdf177dae0db03569eb04df100ceab1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:2ef033ddda965b957d9dca417cb35cd5ffb5b4f25a91b12e62f04a74cac8aca0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:a22d3dc63ff65d043f717b032845f2295500ba34a7d9d5f587b8cd253a8aee5e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:e13989b3f1981d06aee98716fa0defd4b0d0eb50eca57525fa21fd6f783ce392