Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.37-debian-dev, 1.37-debian13-dev, 1.37-dev, 1.37.7-debian-dev, 1.37.7-debian13-dev, 1.37.7-dev

Index digest:

sha256:cc38336d3fe2954f965896b942d3d115c56c6fb1590b76d83f080cc0b66a61db

Manifest digest:

sha256:1093e472b38fe4b2f8cd56a5898764b758b8b5399413db9160c9e6ad11505992

Size

52.37 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:85889c65abfd17255d8cc737241ae66fb5338fb73fbf92392576321396d78da2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:c36fa9a0e81680d3e0deee338e960e78aad2b602f31271438cd3a6a14e6c952d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:0f5d0457016954ce9b1bcb8684ffa92b0824d25f01cf65288f19b982684a066c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:51432eeeab912d3b6949da2febf315013ea324523cb5445949e2d286c8c3c265
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:30abdb98acb5a29ada6e614367b63a2ad9708638d615b396593a39fa06d7d9ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:68ce2569ce638e597bad200352bd294a94a0d957f9a4b9d6472a3dcb66a05a04
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:aa1f695de9569041b6806577bd3eaaa58b4660e855391e0c613c1e4fff562205
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:30f6f04a51574cfb6483ee3c63293de6584a31119dd3d1336c760c1cb3ff6225
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:186f0d4c66a5ca7c4f2ededb5cb5348411f2c41d257ed04330cc2bd8309d77dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:38c73404d02b1d017841065a4a0525a9e324f0251686b30fed40f91eb8b0bbfd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:63c449c13ca2563f87cd5fbd91d2840743b7626d9d5fb02dc07add0a5b8d05c0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:0475355915310a29b48aad4922387475c61ef7f91b4abe7751fe05e43c478ee8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:1c9149595baeef889cfef0bbd71c7b5caf729491cceb991876839609b6cd5bfd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:181e48f5c0764c6a85c69a516fd337efa36f876da777d6bdfdb58cad10cc30bd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:9baa72d7862f87e8654a01c38bd9ea5e48d54e0f966513d7629757d6f19f8bc9