Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.8-debian-fips, 1.8-debian13-fips, 1.8-fips, 1.8.4-debian-fips, 1.8.4-debian13-fips, 1.8.4-fips

Index digest:

sha256:474b04d96ed205f5fc13c9ea33d516f7c43c64d8d822b753cf9ad233384aebe1

Manifest digest:

sha256:38cf0e6dcdafef431458cbe2de126f9a6372155877addd4eadbc8d4a97193753

Size

35.67 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:a83b1a3aa9891144fcaf7d8962ac55484e2e488d0a4e41a2e49c99e7fda97b7e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:3097d1d283c0228cab156ecb06f36b5c28daa7f628ccd6622e628dc3db1635aa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:1dd66cb41c22fddbfe2b673df825461d7608f2305cf713b929b37ea5e86b04c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:9e0d7cd42ece57b9c6a067df9ad6e9c8309476af1f6d771b525edfae21be141c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:11dc5f15ba3dea6db376150cc3ef444f61cea8b65828ab5c41ecc8b24f850033
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:e63e6642e10f2f2bc5f7ae4e4a98b9309c164ac83770d92caa14fd905717c0a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:49c609fdc4f171b50cfb9e1e4c6c0cd88a308b3a135689f585f65578f3dbc34e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:b340744853e6658f627ad7c7eed122e53f8519d8b80ab807ac3b6e6be1a2d2b3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:a96bdedf3a79a1aa40afce61dceb6b8b91a1d008eab104a875f4e10486874e98
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:f78084cb6edff6adcf48424ed74090662561168fe18fcd271aa13af9053df3ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:77daf62855af019a0aee5fe1247578a0a2aad9181eca10566e9d2d92b14f908c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:8ccb35fd77bb37a3ebee13525e22c1d767569e15ec8343749a5a5f8bba36fe8c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:6c5d34e429b1a4db1b2268e349f2252f1eebcc7e3298b85d4248b8478986e644
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:3b9c4b3e8f74901ec259e22a0b6d8d6dbc4061592592c97b4df6262a804e4549
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:527630ec7eaadf8c7d2555b2735861a31449daac0fec29ab51536ca5b00a3cd9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:95c07ec53c33a699b2d1ff295fe3b48714e54ebf9001d849d93baf2ba581c405
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:524cf87b2a91dc5bdc6e398633441cd04ba812328b8788d3282b98319fe33e34