Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.37-debian-dev, 1.37-debian13-dev, 1.37-dev, 1.37.8-debian-dev, 1.37.8-debian13-dev, 1.37.8-dev

Index digest:

sha256:dddc4e3879e8b952b7108f747796fcfa6402827dc6f981a9475a416514e7b8ea

Manifest digest:

sha256:d3119d5d8bffd38bf53c6299ad9724b0ffcb508929f367b76c84f9e0d13a9155

Size

52.41 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:3792cac0ccf3130b524f207fc724531bd10c356dfc53c12f474637942010229d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:2de322824335c7fd128e44ba3b4b66058db826de502a2ec9e62862dc6c142a40
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:b302e49aa7893865cce019ae1530b9f72c77adc94888f0f3b0809f1c0088448e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:8bb08d005d3bb8fe777616c8d5db2cb82724526ab7055f04a0b4deafbd9dbff9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:2b6c2e5d8ecada1c74b4c9fe3324539a172bc73078897adddfe4be051bb2cc40
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:197dac4d75c61edefff78d43e46169ecff986bf4d48591597d633d410e6964e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:91ed1777b3ec2347694ee42f6e80b9f69d92ce19d5a3a5aa95a754c688112327
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:d6cfad32524001002b1baa359b0461158c9a9e5ed52efb62a35c81cd3115e461
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:572a5c0341d4d9cf0701cae8eab8d04c9442e0e11320b63d61e0416f17667de3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:06dfcf1d85704a319d4f638e77cfde709850d4cc487c677efe7baa850b22a9ed
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:847e2892b6c088d7ca967cd54497f4602878ad45667d69a30946010000ce97d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:fe052200b0190e95fec2121e8f57f723a5ea94e053fcaacd6b56248c7a150fd8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:245e29477b0eb925c8f160d7f07a12aeb08e853dbc7192764bc186d884de75c5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:177d60b11960613ef4302f0ff0c527a633d6838d56869edf8b794193a41c9826
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:d604a83154503eb8c5d47dfaf0a06aa58332507c2974e96cc6cda318566c3272