Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.8-debian-fips, 1.8-debian13-fips, 1.8-fips, 1.8.5-debian-fips, 1.8.5-debian13-fips, 1.8.5-fips

Index digest:

sha256:634929a2152627ac437641a4bbdf045fa15a52ef9b282d210663192c013b66f8

Manifest digest:

sha256:19fdb286bd820c4612a360812f79989248f0bc0a810d20af8f725f4ba4c238b0

Size

35.86 MB

Last pushed

2 days ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:2188ebe4f7cdfc419512ee509e8330dd782ee68fde36184babbc97bc6940aac7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:8c2f7a58b551cfc4b95f6f74e6eff319ba3e1f5912dfad45a93cef29e7a22a23
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:6cfc52eb1322398407613bb37c1fbe67dd202c3182e676879d4df6daf0c9b15e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:e5dc3696a0c131d67433c2adb4632f8a9b45703139a8a3d7967037bdfbd7e3ac
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:5cbf132f8c4baba5613db0e3b5a35c59684bdbcc7d01e15acd2ae5651bce69bd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:b3a0811689a5fd185ff4a0bcc9c459418681f0cf72a13d529eb7053b7d232eac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:742e40fee51686c5caa499b9aed28ef0dd863bce507910ea9d7e18cd0506a4cf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:bf3f9a284ff8f3cc94d6c2e69701d0f84c13e372adc449afccf2b6bfce6f7bd2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:f6175a043bb4d4db8367f4e1876b6f3fd72044fa74bd1738e3c00c681c6579fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:444fac8752ee65424bba32e34a78ae9b39467ed525ea643a7a30d4aad5c1e4ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:6e3a9e35eeea1ad60226345db482ed380c4346bb7af5eacd4ad0318e9378de74
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:3db69cd6ddf923b3b70eb78f92b8a9311d2a3551fd9d5560e3cb105dec9797aa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:decdead831148c2ce3160d469a5ee2d347de653462628e365a1daefcf16500cc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:77320b00b0a3d8f7bd2d7b5c9d66ae267767c295164606bb16f322f7d4c31d43
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:9508e101d56a7f25f848a8d8d8014d8920ce596841270b3eaac9ac04d38ab446
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:4d750c00a5a1c964f92c84ad6a68ace18d2ab27b8cba7260dfb5c3b9a6b43eb7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:e64308dcdc0a4602c42a22a23ece63bf52269804a464e73f50e6f523e53c1c85