Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.36.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.36-debian-fips, 1.36-debian13-fips, 1.36-fips, 1.36.11-debian-fips, 1.36.11-debian13-fips, 1.36.11-fips

Index digest:

sha256:57f5f99af814043a9bdb3c38957cac52574ae6277cddce34f03f984ef15091fe

Manifest digest:

sha256:95cd3f6570eda6cfc51ef8e47b46988866cead7a951ffe2eb830ee929b3c2655

Size

36.79 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Ends Oct 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.36-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.36-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:4bdb07d1be22e469dce09de167d62caa5ac15268fe2f2a2f3e5dd953bb962fcb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:b96854519143eb2e1d4999d849671650df211900a14369842bc13e4682ccdf0a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:a6ac4e66c50f2a5fbb8d8d44e327886ddd86b7bb247197f5d2aaf433d57e38be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:bd49bbeeb1d433eeb5f922094d0e4a7d0a5f1bb3dc0b8e53f2b8a5f8a05118e0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:597b0b750ec0c36fe7b3116c4843f103c8b7069482603efad6e4c6f6f246c78e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:565c15a8b52f48ba5b81b1115c32f9166919e6a8b622c5e422e0f8b2861f9518
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:86d0344d1f25a50d81220ff8768ae22227e8e145d260a5875675510d413988b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:f6132e775869d71241ffe0e1ec1e8cdbf3b47536cc56bd658bb76674d4e3545c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:8ccda1aa743a45b76309032095d17f376913c1510dcef132d9d11c807137461b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:254c502d54ddf26bcfde7f0db537d3b8ece9b9b33398859a6676e8ef219b776e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:41822155b0f858bec7334e65c3dcdbb9efb418156653cfb9a5d038bba1fce6b9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:5b0cdb18d04667cc557851b5a12675ba750a5d2622b49690e2448fe32c9276c1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:03773d3b9a71e9457520522c482fb96dd6cd35cc9be02d620f6f2122618cb420
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:866f7b70458d2e4960eb54171167252c6b6838e928827f3c1f6f7167ca3f4c1d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:7f506d74a2b0941425ede844220625732b8b025828990aaaa3edde6db3ee45ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:9a0b60524430fbee821b8df386d4ebe129e4f8a0dd7b56c479baf3f6992519f1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:4c2ce30c115360796e6ea4387f57ac2257ac1d41f334e2ceeda5210ddbe43dd0