Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.39-debian-fips, 1.39-debian13-fips, 1.39-fips, 1.39.3-debian-fips, 1.39.3-debian13-fips, 1.39.3-fips

Index digest:

sha256:5489f176a53752b91993de57dc70b01620ae45b661909ddf36a651dad6b617c9

Manifest digest:

sha256:e40de356af47c1b85151c07347ce37bc4d984057f62a846ae5861425f6fcd693

Size

60.46 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:999b0965729ff707606e719000df09068189f4a0b13e8975d87a865dceff4d1d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:c290cc02b22b9fd2e5bb34f10a5827361070a11fc03b2df7d73f6318ba6a3260
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-contrib@sha256:0752f7200c7c108fee461c135c96cc13fb1718c128af513213001cd3da22e96d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:194df1cf093c39a8d18d692d878d904e6540ee980f05fedc2f38336df100ca6a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-contrib@sha256:4551f6bda83b78ea1aebdbf3500c4ef5bbec7d9dc5664720282b9d8f230d82b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:45f42393c9fa8d4771fa66e77eb279c3300a71cbc98dcae07bc637b7a2693c56
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:9a8030108db16da6b1a1d9b93befb13b70caacaf7eea30b6e36979eb90dc7dbe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:99a4cf0b168da0c1d02ae4636b6d3303487cebaee70df9de087c3f73adedbad4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:5003a0688a4bb95df5c57d8b1a13cbde4df52ced7506999cd362b2d11ef56f6a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:25a6543431fcacd8d6f026d9afe20415904a1084c7935a5a032b06fb0074ab2a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:6b8d4717d72f57abc2245b8d7a3e846b53af5339e0dba86d46dd2952eade843f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:ef115ece8f57d1034eff676e3aad7d84ab9567fe3b41d785c8f90436ec2c34ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:ca491cc5e69107bdd67fdc58f3f59491c2f46a501757a4521f685e49d427b648
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:0d345842a573b63bf1c742974b95b8575f6fb5459ce8862b6e29e9f320b7b8fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:ebeb1e935e82951b2dc807fd5fb50a90e7d02263d2393412d5eaa3ceb2d7278f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:99eafd7d796ab3b9279d30867917f0de30c03c00001b5b4b96ec2b10af9289e3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:863e283ca15d8ce99f7584dc7a1ddfd6a87b20acb3c89df3039a2648654d2aca