Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.9, 1.9-debian, 1.9-debian13, 1.9.2, 1.9.2-debian, 1.9.2-debian13

Index digest:

sha256:5e59d3741e939ac11bb48bf274098c6d0c2cb2ed4818f5269682f64869728d26

Manifest digest:

sha256:f2ed3d0b99e007fdac72d8ec56bde1de078ab6ff5829b329c709fde4a0530a37

Size

27.84 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:e5f82a2651aee02d6398bcad4c70d58163170eced82892447aa9ed5c9a44de2f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:9c87d5a1e76270e282db6f3fbe3c4d1cdfd796c5da3fae69d4a41aebb96dc123
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:512745c43fcb477bea9f3d25fcf5293975c0cfce6dff012c17ffd7ba83e5cb76
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:0b3eddaa7e0301a8ca93edc2bfa69c9c3130bae31291f176de01eaef91443d04
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:83ba9ee3838af8882a0c82e63bf79b87c7b58cdab0f7907f8a402e1ed687781a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:b5ba87599a91975c2ba42d7d706ba20dbca2af37b354c066837451b56fc4320b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:f4c04e0d12a0da2b4a91ea0fceaa6ca200a5e974236e79327888e2374419298e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:8931b7aa3ec6e351a188ea564e3a1fbdc2183c2a55b1df32028e10cf8a5c7d24
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:6448643affae4d390a2e650d2b521b7348f74c3874d55b45b4d13b3540a668fb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:f762c1452ff8a4cc304357ec3586566ff017474b79a466b121ece1ce527457da
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:2be4c813fcbac7a4eb60540cc849b66355c1b5eabc6e83dc3a6e91bc0ca7beed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:1556cb7b23d57b096ce163bfceea2f6a8f30a4656c3c40dc2c1d5da20b3d358b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:5de73c65ef1e17e224114b0a5d9863bfc074191924fa4f1bb144e94d1eb51784
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:48a12179bde44bb0452819defdbf08cea966d893f23047ba5e5dc6f4c50a1111
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:aa0be4be35f9f2c32f3cbd7a430a50f385d867e14484bb3996c19cb767513ad3