dhi.io/envoy-gateway
1.7-debian-fips-dev, 1.7-debian13-fips-dev, 1.7-fips-dev, 1.7.5-debian-fips-dev, 1.7.5-debian13-fips-dev, 1.7.5-fips-dev
sha256:f8dbf7aba11a357b1ebcb43d602511fbeb13d433f124e0a51859eb050875d40e
Manifest digest:sha256:73a7682be14f1ed674be03b487051f5906bca1358be3aae3e72fdcaa73db7149
Size
77.43 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/envoy-gateway:1.7-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/envoy-gateway:1.7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/envoy-gateway@sha256:d9420fc9416b5badf462012b7688064cbf36a2d370589b89dc5d1437b73d1519 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/envoy-gateway@sha256:0f7b8fa856fe2747e903200a1ec03a4605ed2d5dc1cda286c8e9bc6470f19e42 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/envoy-gateway@sha256:a840ff4f6e03cffc6a12bde9076d23d27ac7f33253a55f51e472c540745fb726 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/envoy-gateway@sha256:9b367a5c679a6ac34804de3911cadcf759f7065eefce9522ce0c7ebe2684fb39 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/envoy-gateway@sha256:cc3e31d778482428c19813813ed837e0dcb434d87eeaa15dcce83a7b802de063 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/envoy-gateway@sha256:f9f2792d672fa032e1ee83d00a689861f8f24387154315c04e5695e4dbac28f5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/envoy-gateway@sha256:7be4af456daf922201dc668d676ba47280303bdcd1c67edf7e9d18cb0a413866 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/envoy-gateway@sha256:dd130a79bb6931a8792f95c3181f81e5777cf1a219abae8daa9eb66ef16be75b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/envoy-gateway@sha256:2fbdbcd4d2ed7388ba6b3e4719958c1be6c4d081231c5fbd09bb904b4ad5ef0a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/envoy-gateway@sha256:db0d2305570b355ad25fe34bb1c8a134a2f2a5a394366bab1f6086ff2906faa2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/envoy-gateway@sha256:3f6f694b813d8aff9b6f25857305cd3713d4fef62bfa90b3397a83798edde866 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/envoy-gateway@sha256:899fb0cfe83df02f1f2c4d9e1b5b82e5f37db5dfea6a7ada2c5db2441a320672 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/envoy-gateway@sha256:9e4e3ddc381b50ef6c0d59e5d9a739f37ecd8b00944cee588beab8fb343eb234 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/envoy-gateway@sha256:0e1feb804e1268e08d81b0f81fe794e65d70ebeac4bdda2dce66c9aaec565733 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/envoy-gateway@sha256:0e692c09606934e2127647939a75e224d50658b62275361efa17edbd3f096a9e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/envoy-gateway@sha256:f86ae29ba64442a277a8eabab32ac16f0bcadb7d54d1f17cbbeb39f7046d1257 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/envoy-gateway@sha256:85a47689d59d17701e52e0b4bf730b0da565c2e34b099c58cb5f4783f4d7430b |