Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.39, 1.39-debian, 1.39-debian13, 1.39.3, 1.39.3-debian, 1.39.3-debian13

Index digest:

sha256:cc128371a98c115b77b43d15ba10e3debb6f0b5558856c26da2be1716c3cb316

Manifest digest:

sha256:3a87462c10d8a31c0e6a31111038d1a76950e31106cd8a97162f746cdc2a2b57

Size

55.28 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:cd205f5f383f7336a00f263459b7ea5587915f825f2f251ab4b1b1e5d475dc15
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:cb123675f0f036a4f407d8436b35d1a9ba56271c8d5f1698d084355d5562ab20
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:ba747449194ce3c40c65fec4f557fc32e729f02818170ac6c465396c70193378
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:fe2219e170b6d6a6f78c1785adbd4c66a4192000b4264a8aa57bfa8b156f8d13
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:8f9a24470c9f0764a49e358acf1a1e5e50c233a127cd589f12407fcab6de8e37
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:8028be811404f9cd96005a25b08fde0a27e9bd4d56a70d054345be75cc3dd2c7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:aaffadf22887363089a1f91e6077adbcccbd5ed51cc6a0c44ce373fb0e519e45
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:361140e9b878f8bc62137224e4e22251baac875d2899df8a826f099d56ea2dd1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:aa9c24725d8c8e312c61a947f1bc5a5e7e19c37aca5208327f8d2d9b81b548a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:9d9e84a19eef5b0b4621335b19c6e20668403fa8140110ad468a396f28a2c16e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:b782340092ade0e86ff80ffe4bbe79513bcbfc88ec35d58b3d336b067e2d73a3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:56648a0c080ebcaff04b6269b6bf4ab61adc96373248e53e187cb2000ac412ab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:2530d9892e2047e045b62a366b21c97b5857f85a5584d22a4b9bb475c901ede2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:969f0b34b571621ee6619a7b0c426b37f3ec851c28c2714a08aff916e7e11ef8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:8fd38b333667fa6661e888f180503daad9491c2a9d8c778a50b801e8e6d9ffa8