Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.3-debian-dev, 1.39.3-debian13-dev, 1.39.3-dev

Index digest:

sha256:7dcf65de8266faa8e64ce6e86fd1a2ae399defeea2a7a79e52779a77b0aefa05

Manifest digest:

sha256:a157c146914fa6a5a50bce2a1fd2625b5da47d9146f18092a389f699782cc0c3

Size

74.45 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:b1dd6827936156216fa5295272f4dc2342c8d537f63cb016ade8ae8a6035f88c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:fe6f55a66103eb329e98c1d79d9705aab8f3a0a766497bdce4a38ae48f4fc977
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:e067ed73fa1ef208d2ab224709a5f9502dfadcaa8c7b544d8452b5a3d9e9aba6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:9fe5a116bcedd5bf6fdc4f7db49a27e673291f63f387c1adb8ab5437c2d6fdce
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:edd8279ce4efaaede7c99ce607f041c1797cad7d0942f2aab470777affefa956
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:34941465c08dabe461d94e9a3f64aec4883c7e591719594f9fc5fc645e48aa07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:cc7232fc52b5313cd82ac4e268a5d05f463d9a77eeca84a0f1566e159943f9c8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:acd0971c4e74a80d342b01df711a364f453ceaf21511892792c4fad790c86f34
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:1e041ce8e6f16c69096a33fd4c9105143c3d842c6adc28d67e6d54cede0df235
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:593e946936a03190979bd30edf19760dea650d40f3ca24561116667b5e886512
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:5beeb7aa155dab61fb6ef94b6b63e426ecd6cb785ab45812749f80ecd862f9ea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:9058eb8e91667945eb25719e530ad00b060fe88f8cd6425dd16daf6d7a7c1116
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:e6dcb0915d3ef9106cbb53084e0f1f2b04379bc0c8bf5f95ffc764023c6e81d6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:14687a52f67d568377e623f8e7ceb3f395ee127f9dd9ca669205299f778f2369
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:998e3ce4689da5f3894a7a817fdd740a22b5b472db7be426af5ed7b3499d12c8