Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.36.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips, 1.36-debian13-fips, 1.36-fips, 1.36.12-debian-fips, 1.36.12-debian13-fips, 1.36.12-fips

Index digest:

sha256:e38623ec2d8347e2be3049d3b50deb1dfeee8429f08014101cf81dd918fe3a50

Manifest digest:

sha256:4e220c93f27be143161bd0d5057d0a40277f3e376958306aedbb2d0b2fbd3103

Size

36.83 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Ends Oct 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.36-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.36-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:d7ffc75998f244d898f9a13f03583bd7b548ef52428126a712cfcfa3871b2f51
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:2d778564d64172e4de8005c0176aa8a36425fa0470fcd7c9a10348297a3de036
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:ad3a2e0412245bd8c63faecf318701046664de2c4343a44f163540b51b7211da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:23c942e38fe6aad18f24f31c7c533b1742c8e72defc120cf9797e0222cc00353
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:34fa53417e18690e46a5df7aa6a05856201f0946105fde495277a19bca861e16
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:6d69a05241eb1092a2f1bdc0ea2524a1ffc68fab8f634299a3e1a718ebae9a13
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:3541eeb02fd951078f5f0fc2e995aa3da2c6c85c76b922fd5baf9f7c6034c370
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:c89c1bee4781ba50d520f093d351791524e4e52ff26f037567d73c2ba991910f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:48d1e091dfff471b6bda792c4476ff35b61cb15b8fba2b6945132a3da74f5977
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:1cd9dfde25fc3cc5b3147286bf3166df7ad1acb5dbf9418a6e9c2103d28134f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:f10ae2c0d4793509cf7c9ec75e118752d1d9ec77ecce9f32ada380b0622c1089
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:a5a15b32e41faa78261fc99231e02d297c2286978482525b8bed37f96b02e7a3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:38ed1a4101806b2fb37cc2d9e8a92ae2bad26d337c887ca3aa3dd23f68064cc8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:28ef02c40397848ce1ae32c78988c55b56f369a06b8c962936e221bac1e0e863
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:744d3f6c9aa729432063bbc34890b4cf9321ac14a97a1f7146c1be93317b8bd0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:0cad2341b2cd907708bb8d1426b038f41c6027124c861624d6ef851931e08422
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:42ceeba62f901ab53893f242c5fa7aa9b9d3ad79a46b5edda78b995be5f20e5f