Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.39, 1.39-debian, 1.39-debian13, 1.39.2, 1.39.2-debian, 1.39.2-debian13

Index digest:

sha256:233a8a81f2e0a463876ac65fc8152bb4216b8fee1c35a8c3bde72ed2799e42f5

Manifest digest:

sha256:6c21c263edc2a72542d3e050804763dff079960390644a304d9f9d7d5bcdfba4

Size

55.25 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:6f4123a0ab0ab7de8adb2674ddf3a8e8df65c04815b12b15545e8d5dd874f894
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:5dc14598df5e34b9fa3bbb245fed311fb2ad8ce8ca48ab306fca41d38f59ad58
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:7ca2b6e243f1c29d51a554cb611e0498ea7b52913c82f644f81a5847e5b91181
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:fa52bde54c791b3019cd38fb0505753bc20ee6515724a4bd849a9218ff0319af
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:5e0dde2b3576397070b956420f673e1d68d3c7ca694c0f8df06e5545ce75c188
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:25412b67b2c6f9ee257c98c32e8244acf1d99c44c0ad06f22664e0ede02f893b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:15b9f20dfeeed2d7fb7948dc377d28050d0230473ead32ff3672f666f2b5a011
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:ff2458d4cd00d3d9efa65d1d1d2d947e56941411c2e8005b0f81584e4e499be0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:dae49f050574cb3d8a457a09c461dca460864efbc63e1f5db46350a5532fcf55
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:0ab2d7bd33940b9e0e948fbc2e43c0c4d3c1f4d2debec09189cdfd8c265aecf3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:92be1a1ee1f6e852cb1ee5974e0d2ababf00a7abc2fb253d80069fc373d3f75b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:cd121698e47e53986f3ebc53963483a757dce84c3f3ddae06ac42ff36cdafa7f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:b72ec52248b8dc360292e94c76f51fb68c2203468ac3fe9118b8ac2a25ca466d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:9dd566b1f4631a75a7f3a913a3407331819ba03d5a263e5a979c5139c8f45bbf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:537be331ef977b0a2da2e4ed8d453c8f1a60d02da4e4fbbd38d9e33a1cc6315e