Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.36.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.36-debian-dev, 1.36-debian13-dev, 1.36-dev, 1.36.10-debian-dev, 1.36.10-debian13-dev, 1.36.10-dev

Index digest:

sha256:2dcd64f7b74545b5e0b692b99b426c0abf0523bd7794388e15f7730695050beb

Manifest digest:

sha256:a4c09b163109e76b56c7ca7309e345774e7702eeeaa8f64bb4ad162ff621c3b7

Size

50.79 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Oct 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:9abe53fa2f1698f348f8a5698f26b9bde9172620c031cc06d6007d5fe1b608fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:558aaef5719ddb1e4120416f5c62f0f043e86dcce0fba3b867be77558248681d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:435ca2e14acfe895b7eab121e6b6241dd45b2de445cbca1780a6de46a34cb15a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:036695cc30c051726ad8020dcf0278ef0fb1a389c39f409439946a178f24a4d0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:3b7fa3fbfd887879acfc6dfa04b6f7032b9d7de0639bec27b34aed9fd8233d1d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:eadf802db79bfcf9da5af69d2b6870316cc7998c0348f83dc26e4721720847f3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:b9c7bbfd35df67643e9f9bdad0f69af0d6d0f664375792b61abe1fbf261c661f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:250c2b4317b21c5d4ff79aeaa185ebac27c63037eda73bcefbcadf6d6b8f7a6d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:07d25cbe08123c1e2f4406fb65f10bc2b85f1a31df76f863f92b7fd0c84e179b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:ad5de6aea85dd6e267ec46d8da6adf2ae0c20cc22ac3f4ec57ab4645cc137b0e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:825b4fe2b82d398ccbd2734bec6357daf98e7460fd7bca16b3e5cb681e94dadb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:2981380b0b3b6827bed94059e45e8136bf91a071f53e5d3d4ff88a99641d650c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:6530ca1ffc4da701846ebb54e00ffb6cef15bb74c877b769c59f9cc30708c9bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:02959a24948c1b85cfcc42f2c9b083b3a1dbf26b3d11c29d583cb3fcd68ef12a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:e9e243a83725881f3628a8bd07bf1d91c377c43c89fa0fcd778dbe3ac87c3bb7