Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.9-debian-fips-dev, 1.9-debian13-fips-dev, 1.9-fips-dev, 1.9.2-debian-fips-dev, 1.9.2-debian13-fips-dev, 1.9.2-fips-dev

Index digest:

sha256:98138f961304a3b7cdc82c26d174b8631f053c7ea9c8cfb63ff7d466e70c7a38

Manifest digest:

sha256:954f176412b74004d464d79cf4b4abfba1de75b58d4791173b195fdb2e353ba9

Size

77.44 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:f4b6a1b92182202f5b0278d49407df041e831fc4cc7cbf913d9720274f155b1c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:8b77fae674a195ffe5c679f7b54f41efd6a79f8127e2809ec12848dee5c098b3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:50785b54e4959ae31c3e8c6e2faa41a970f8e14de7caa32efa9e0cbe4df116ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:2bd443d3149cc15e779f736e9bc7909c1d763282a726420bd1ec6487bd0243d5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:ec27da14410e2c3ce70703f27096550fa5d903ccbb30c51657c56f18551050ef
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:b8c76e43b6c25fb93b137dbba3fa99fcb317324bc004172433594a5f00a6c678
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:040751e1b5a4c1d7a56fd8e15c91820c0191e03b5182b633bf1966224ebad47b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:26371fe080c7ee489d1c5a2e45dc75ae5935a17a72da527c429d7077aa3a2c1d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:a59a677c84259f0c48ea78269bc824194b1eda1eefdea38cbb5890266b57e4f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:b7e2e413e5816c763e44145b9dc6cecf0727382c24b7ef95c5a08681a5072da1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:14b257eb7ab78839b58cf6b7802ce1386e6381ef557d61919d9bc9b3f42c1aaf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:e9b6cfc3db5dd672a4029813859624b0643bd94aec4ae744c2c50a9058bbb528
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:92a9666f25f34529684ac7363602c85f1c6e695f2adadcf83ff833c430e32323
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:177e25667548cbbcd21ba915e0f5dce88dd2788e5a5293d1bf5500907adbf0fd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:7e7b7020b457f60a2af2b05d8def1b63eb24e819f2a26244f7e1fd11a5d1c7e5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:80b7f0c9a4d419fb0ecf84c9a91dc2601d51824e197f6454ff3429fc21f4f05d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:a1fee76869eddff873a4cf7333322bd4f47f7c01b56a5f934c918e34e65e9da3