Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.36.x

CIS
linux/amd64
debian 13
Tags:

1.36, 1.36-debian, 1.36-debian13, 1.36.10, 1.36.10-debian, 1.36.10-debian13

Index digest:

sha256:3208496e07372c5062c144ce76992c402df5c9ae1e0c6df5dc0cbfc13bd59e0b

Manifest digest:

sha256:0ab7f365872f9b75034c31123dd728add02867e3a96a7340ac91be2643a764d6

Size

31.61 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Ends Oct 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.36

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.36 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:96e95d54e368e525703f5e02bab33606554e91c48d49b79a2f883a2e5b8a101d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:112c0f7ebb9f8cbb20db3d563c1f0f225d99f940a91f50bd80fe7f110447bd6e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:036498ef3cf8d4ddec79da1c5f923eaaed3df9955a85a1a7e17e5283d0c63a68
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:594a9e5367a81cb477c197592b304ea960d92871f3ce3329d9781011ed214de5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:17bf67fdedb5b5c2212f0f9d3de6739919de886a9c0b22e6b4985e4b635d1bc3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:ac4c7caa75fc38977d60b6705959a2d71671e2f7c43039f2945444306cea07c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:362764a39402b6f6b94b2e4ea21d27e01c5e063d954e04c096c4d8edaa5103ad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:91b453e632161268d012ee011668027eb88fa3dc53c0a24230496f326077a9aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:eca38a361bf73e387aeb79d7003741e1bca3b4757879bf8a6bbd7df715c52b37
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:785a22d6c759444a303f5aff43236df7576a4cbae7462aad06e40fa7fed3c961
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:6fa79b4e46263df63c9f5463a1c22273c60305f0111f0bc81c6252512f25e5cf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:1abc726bc539350518fbfba5941e05800b1b0f15ef6ca4c6ca4f0e19fdd2e2ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:c0ed1ad741c3fa0c6f0f725f0aacaadb9615411fc453717f0ea1d9a5e13830b2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:f690044cd4e33877bc923c8a8d838a5470ee4d236f93f1c6f4835aaad75d0ffb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:6e1a3d89b314f8e57c0a8543b7f7256e025621d45646b02120b286483b0488a9