Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.3-debian-dev, 1.39.3-debian13-dev, 1.39.3-dev

Index digest:

sha256:0263d3bb45abe5c3a97eb1d0606891b493b3bbee2f3006b68f25d03d86ddaf0f

Manifest digest:

sha256:7401237e1c924cc311c957221815fe74e1fb78960b617832705cbc04913c6e31

Size

74.46 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:9700e74b2b78f0747b6513cd1732f5e88d27fb4af52e7b730aab9308083e94d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:b9f638a9a5e48e6f838485511fd52216a4b78a13d82096dde61bd5730674b3cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:0195a7b0e4846ad9ce6c37a091b90c05d8c7c9d12fc7ab84d44267aaad36034e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:934e937611d0e5a7195085d5aa745369de9e4d69284616f90c9bcce7422c73ef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:6eaa34d8535c7c9ee6566b6e0dd9db09b2f47930bb3ec00ef0ae76f3561422f3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:4099a8bc99c09f0bd5b9224f791e2d2cb88492f9dd1aed50a7bb9cdfcabd63e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:7bb32a3c3b3d900a5394010aa5f6218354c2fe8fe4a213e8718c5cdee1490770
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:9a743eb1bd9144894ef0d27fbb2a5eafd5cc6399ab2ef991cc183d9bdf86c84c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:2c3282707240288fd12191b5d8287664b104e39c8e0455bf7e0233c87e9826dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:6310ca2d64aeab97e1970e48c8128ca759c6efea753b3b16b69b69b6ccd01acb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:080e07544115befaf430be1a88a37767b73e783ede6eb998a8467b762b291d71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:751a4092315bc50456f8bcd162da03cc089e7dca5f30286f9732bfaa8e552d66
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:865c34dafc3b4dbd652bc868d9930e090bf6522fddce42e348df4be5e15b5cc8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:9f3bd17e162db53f23a0502539047defd344bb653a84c5621def91d2259ffc33
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:f3a2f69e250b3aef8713dd4df64cbe0ed42852777a6f08ce2a48a99a08b6009e