Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.9-debian-fips-dev, 1.9-debian13-fips-dev, 1.9-fips-dev, 1.9.2-debian-fips-dev, 1.9.2-debian13-fips-dev, 1.9.2-fips-dev

Index digest:

sha256:a937defe8c4ddfe2057013439d2ddceec6e0631d984b10bcd49ee27fe167802d

Manifest digest:

sha256:f1bb6ecaa78499f7667906f550b9c469998db70b47df192aaf8b8ff72ef617a7

Size

77.44 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:e9f75ff2d77ef1115680f21354d6babb5e78c078322b247e9b6e6cf8ae34f4d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:7dba9e923656d0b2c85bf466ba636d4760fa29cf7c75b24e1dcfcc4e8da80fc1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:5a43d750cb372a4f830a0b5e79c8a89ba1432afdc8f9dafb502298693d699400
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:8263f085ff9fc100b32bc52bed36b7ee1de210b02222d49981a42d99349b4901
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:d13df8115097865d9c721a64ad9a69367540e02c45304884260d57cf9f8e82ac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:8725a5ebc16e56d1248c7d5339478645cda6356fe37ef3ce77c824a680edfe11
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:d1045490cc9e52e6bcf147298c9522cf1f9fc77be4a769373437e397bb7845f4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:c6300688d9717c267498eaa2ce7b7ee715d02ca7d39b1ff351e6bb1892f9e9f8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:51dbed75d4172f81368bf778cfc431ca07c02e6d6b2420a144695c223a903cfc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:4075bce4a0eacb4c3a500f06d8c1adca6ce58f51342dc19dcfb937f8bcd7e310
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:ca90a667f11a3a8743118527a215aaa98eda577228cf0fcb865cbd71d97fc1d2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:c485b376f9d79ff56a097457255e2e54a9cd60f55514905460430c0ea3a3489a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:03ca711e98f60cba9f54e326edf1116723f0f74f91f7b1f3ec11b7d18450029d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:806552f2d2e29dbfda862c6e3622a370fa70b4c17bf6b56827b3d4284f8a574c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:94f9f9ab4d19a4afd611e53c789635e52df8ff9a8b9310a3f41e02d49faf4f88
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:81c567a1e399807f49b4331af2a40440d63986d777269cef8fbe51007777c23e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:9289251770a5214f8ebd8983561035b814743742cbadcf5d6507997b24e3c825