Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.7-debian-fips-dev, 1.7-debian13-fips-dev, 1.7-fips-dev, 1.7.5-debian-fips-dev, 1.7.5-debian13-fips-dev, 1.7.5-fips-dev

Index digest:

sha256:f8dbf7aba11a357b1ebcb43d602511fbeb13d433f124e0a51859eb050875d40e

Manifest digest:

sha256:73a7682be14f1ed674be03b487051f5906bca1358be3aae3e72fdcaa73db7149

Size

77.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:d9420fc9416b5badf462012b7688064cbf36a2d370589b89dc5d1437b73d1519
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:0f7b8fa856fe2747e903200a1ec03a4605ed2d5dc1cda286c8e9bc6470f19e42
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:a840ff4f6e03cffc6a12bde9076d23d27ac7f33253a55f51e472c540745fb726
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:9b367a5c679a6ac34804de3911cadcf759f7065eefce9522ce0c7ebe2684fb39
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:cc3e31d778482428c19813813ed837e0dcb434d87eeaa15dcce83a7b802de063
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:f9f2792d672fa032e1ee83d00a689861f8f24387154315c04e5695e4dbac28f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:7be4af456daf922201dc668d676ba47280303bdcd1c67edf7e9d18cb0a413866
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:dd130a79bb6931a8792f95c3181f81e5777cf1a219abae8daa9eb66ef16be75b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:2fbdbcd4d2ed7388ba6b3e4719958c1be6c4d081231c5fbd09bb904b4ad5ef0a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:db0d2305570b355ad25fe34bb1c8a134a2f2a5a394366bab1f6086ff2906faa2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:3f6f694b813d8aff9b6f25857305cd3713d4fef62bfa90b3397a83798edde866
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:899fb0cfe83df02f1f2c4d9e1b5b82e5f37db5dfea6a7ada2c5db2441a320672
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:9e4e3ddc381b50ef6c0d59e5d9a739f37ecd8b00944cee588beab8fb343eb234
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:0e1feb804e1268e08d81b0f81fe794e65d70ebeac4bdda2dce66c9aaec565733
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:0e692c09606934e2127647939a75e224d50658b62275361efa17edbd3f096a9e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:f86ae29ba64442a277a8eabab32ac16f0bcadb7d54d1f17cbbeb39f7046d1257
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:85a47689d59d17701e52e0b4bf730b0da565c2e34b099c58cb5f4783f4d7430b