Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x

CIS
linux/amd64
debian 13
Tags:

1.7, 1.7-debian, 1.7-debian13, 1.7.5, 1.7.5-debian, 1.7.5-debian13

Index digest:

sha256:c1e159799afdc543ff93f1a9317eda6fbd2254521a8a616a55e0f217490d684c

Manifest digest:

sha256:698e75f1b88a14c3b5082f8a3e8716a41a520cb447e63d012621d05fb25943e3

Size

27.87 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.7

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.7 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:3ca615de213f0d8f310cb45df467e5234bc5873d0402b91976075046d129df55
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:4822c3f17580e9b01e17b32213f8d78fd9e31ece3fc9d6e7bb42e58f9d5abb99
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:d38f9c27198f6fdd252ca23ca112e2829cc206c896eee06364b48b386353cdbc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:6f3ba936108d70e0db571360567504f6114720205b4c086336bbef51ac2ab3d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:9c09c7cae6ceac73c3b6e5047302857564bd9d2dd4b9e2ba243521aec3f51327
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:86ee3a6b94e5ea851da9544587831e52b4ce9ea4e9fb9666816767c7aca042b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:7b5cc61e618149357a9a97bb2efa278fd95cb96846d589b4706779ee4e21762f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:c7c763b3c936855d232fe29dd94977ce93e5bbc4dd597df0c0ccc3b28348fd98
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:5b59a0b1a4c3b618154901f546642498a0f995721ffa374eb92e510247890976
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:eea4b4155582b0abe70acacf4d76325f732043a1c922cc94d6177b3769d499d7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:f5d589bbbbcb7b0461fec935d6d4b54aef7099965ed8bb8ca4e6abf82945b123
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:62af8b8e228d1e8a2bf880d9c4447c36edfa5c1ea8946efa83094ff90d07c9c4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:3be483494b4d246abe0291bec55a84f1cda1d7f0b70b88a4d921c8e3665359e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:0e7f3a895a45838867011f7dba75fccc746ce4ab1a06f6af56665d6d88ba7a0c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:9e1d435d89d3edca7901ce5135e2be5a346b3efebe91c3b38a2b513642558fd3