dhi.io/envoy-gateway
1.8-debian-fips, 1.8-debian13-fips, 1.8-fips, 1.8.5-debian-fips, 1.8.5-debian13-fips, 1.8.5-fips
sha256:634929a2152627ac437641a4bbdf045fa15a52ef9b282d210663192c013b66f8
Manifest digest:sha256:19fdb286bd820c4612a360812f79989248f0bc0a810d20af8f725f4ba4c238b0
Size
35.86 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/envoy-gateway:1.8-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/envoy-gateway:1.8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/envoy-gateway@sha256:2188ebe4f7cdfc419512ee509e8330dd782ee68fde36184babbc97bc6940aac7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/envoy-gateway@sha256:8c2f7a58b551cfc4b95f6f74e6eff319ba3e1f5912dfad45a93cef29e7a22a23 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/envoy-gateway@sha256:6cfc52eb1322398407613bb37c1fbe67dd202c3182e676879d4df6daf0c9b15e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/envoy-gateway@sha256:e5dc3696a0c131d67433c2adb4632f8a9b45703139a8a3d7967037bdfbd7e3ac |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/envoy-gateway@sha256:5cbf132f8c4baba5613db0e3b5a35c59684bdbcc7d01e15acd2ae5651bce69bd |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/envoy-gateway@sha256:b3a0811689a5fd185ff4a0bcc9c459418681f0cf72a13d529eb7053b7d232eac |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/envoy-gateway@sha256:742e40fee51686c5caa499b9aed28ef0dd863bce507910ea9d7e18cd0506a4cf |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/envoy-gateway@sha256:bf3f9a284ff8f3cc94d6c2e69701d0f84c13e372adc449afccf2b6bfce6f7bd2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/envoy-gateway@sha256:f6175a043bb4d4db8367f4e1876b6f3fd72044fa74bd1738e3c00c681c6579fc |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/envoy-gateway@sha256:444fac8752ee65424bba32e34a78ae9b39467ed525ea643a7a30d4aad5c1e4ef |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/envoy-gateway@sha256:6e3a9e35eeea1ad60226345db482ed380c4346bb7af5eacd4ad0318e9378de74 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/envoy-gateway@sha256:3db69cd6ddf923b3b70eb78f92b8a9311d2a3551fd9d5560e3cb105dec9797aa |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/envoy-gateway@sha256:decdead831148c2ce3160d469a5ee2d347de653462628e365a1daefcf16500cc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/envoy-gateway@sha256:77320b00b0a3d8f7bd2d7b5c9d66ae267767c295164606bb16f322f7d4c31d43 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/envoy-gateway@sha256:9508e101d56a7f25f848a8d8d8014d8920ce596841270b3eaac9ac04d38ab446 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/envoy-gateway@sha256:4d750c00a5a1c964f92c84ad6a68ace18d2ab27b8cba7260dfb5c3b9a6b43eb7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/envoy-gateway@sha256:e64308dcdc0a4602c42a22a23ece63bf52269804a464e73f50e6f523e53c1c85 |