Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x

CIS
linux/amd64
debian 13
Tags:

1.7, 1.7-debian, 1.7-debian13, 1.7.5, 1.7.5-debian, 1.7.5-debian13

Index digest:

sha256:7178c195a3e4ce999b3fa314e6f925b898613c1605f14866b5aeb5d025cc6fcd

Manifest digest:

sha256:050ae2bf308141374a00ac18f8e87b608384946d2096289199c08cfecf130fc0

Size

27.54 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.7

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.7 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:4048ec5fc5813e01bfa62d5c0a210669ed13256ff2380503089ef31405b17dd2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:4b059aad44da5f9ff3fe44940e6512b8d8a11f65ec0ec698b4d1f5954593a942
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:ec50342ac43f2881763bf6ee9712156ec3a06dd3d35d53b93f27d5c127fe5950
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:29eda605bff62817a4b269ed680c7ad36973a72f9e811331c94d476bdbf27b4a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:9afbc02b4b600c2b0757070b9bdabe0be0819f893c3d88d324a00d28820e4d3d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:bef176eebc73910f0c1a37daf786ebde109a773d0f67e93028b92cb6a6108f01
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:ee76132c94aeacde30f4ed8e2936fdc275e76404d9fad6ae702c696aaa113cad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:6e5a8c1c12c5024b27cd935464d47cafdae1aa9fc02cdc0c48354981ba4a96e0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:a25a6f2e670dd4698fa4e87f98aee299b60b0a11bc8a4c89e1a4fcae67902851
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:062b8131e87be3474e826b1507452faeb5c3fb1e4651f1ff57bfe217c578c48e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:4ae8af4d8726ffecb5085e09679c04731f45d9202f145a559a849e57d2a3bf7d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:592a3c7ccb63c855278f03cf53edd2ad50eab8ae1a98a22b3c31dbfbbc844353
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:6afdd8fb7e285419b32e7ffa80e4295c96bd359b9ca27db5840173fbce293e90
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:b4a86f3ac01c1e89adaee8c6a1e6fef995f350176c4e49a497b5ad4196e58953
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:b99ab490cf25c296315aecbfc939b49d18e3978ec67bf657a0df2dfa024bf9d0