Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.5-debian-fips-dev, 1.8.5-debian13-fips-dev, 1.8.5-fips-dev

Index digest:

sha256:123e68971dded6bb5d2211dc8448682eff11b9513849d941c56bf759b3c9ca7b

Manifest digest:

sha256:1b7f59578565163260ecd8c84f07c13f83a4f358a76a8b6da2a0a7b5491ae042

Size

77.08 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:2081ea08ebaee95545c94d9d2a219289afcdc99c2e0b0576adcc05a38d446c0b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:0da2ca1decb7db1c00ba2a893a622f5e563a4827a3adc129d24df3c605cde537
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:1fd5096c5c14a2add2e86e1ac2e9736fb6336edf5c6322d6ab0708909ba72696
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:d3170f2e4e0af2d4a8b85e3d757397338319b7352643bc0164cfd05c7887932b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:0edf9a9e12c63e979f9c918f4845a0930f0db6c5a1f8d4d9e4b70932a4220ae0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:45497d089446fc8159ce81506b307945754adbeb3c9f0a9fda11e89278864cfe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:afca2f91a26eea9355765c8066ea0d489ed609b4f033f60ec4a413315070e689
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:cd01de3061bcdd5709ec8c55544d707f368374ee739b7cbfec6f43a5307f5b5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:9601a376c56735d07306903b0d6d4792d6ff44e9f78c1103db3911592ce0ef28
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:2c04d48be1949dca053af53a58e6b555a1d753f1a6f90eb399fc6ec12dbacd91
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:626d9668bb85e1ab87b28b8ab0e7484c317823cd055db65d0779f5e22cd31bae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:28e35d37b919a9bbefb764a38a74a481246fca70b817b7bd16cb7a87be5685cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:fa0b003e619bc97fae45ee76cb897daf92be305a284c3612c814131146d50c1f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:31cf7ae73b61384a37c20aef3e8e4e67a035ec9457230fd10a861168905b8b29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:f606392cf6d16c1e011f46226e755256839deb86067e9001941a1b1961b58eda
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:a097d71671da23338703c8a1731c3530b27906a149e1196bb010e920640c5083
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:5f5a0affa895ec98f0e3c2cd9451ac49c6a892451d9cd978e78a94799db1c7b9