Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.37-debian-fips-dev, 1.37-debian13-fips-dev, 1.37-fips-dev, 1.37.6-debian-fips-dev, 1.37.6-debian13-fips-dev, 1.37.6-fips-dev

Index digest:

sha256:a9369c06d97fda193d6aa268fb828a5ca430f3255b7d4cea5f03cbf7c55819d5

Manifest digest:

sha256:8623488e0f4b060b5e5eed697c45055bb57b11cca777ac4b4633ddd675dd63eb

Size

53.42 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:31cf57a56ed4534fa5dc94c99324a7bed53e4b2c1cb3f10adc3c680f557bee94
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:78a33dccc08a78299908fc42bf723084811e1dc5262df056feed2050446b39e0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:70376e42a6ffde205b63155c5040e76d73dc77be90e2a6d6ea6e6a811a78d380
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:ff1799446ad36f6f60ee543b2f209f3fa02afc7a3beb0dc2eeee91bc875cdafc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:08729a029e23537f28394f48e5ce261c1304778fa08d43365f2280f82901131b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:6faea79e9acc6cd25211d544cd6e95400ed38acceea71a34f356db89b61133db
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:a4eaa4883d201cd79ef7fbf5ce92ec20d94d04e3a0eb0e39fe689322a4b47070
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:ee0208df8bb6ec7d697d85e15d76715b7643a0b88f6e3fd04b631a1a5ee3caf2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:0db078c0efe808b651e94517b23ba1eb40d8bb876efec134ccf1058c9423362e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:8655a4ccaa950cb4a1c41fdc116e6a7ea638092bfb2e8aef354f88f9f8c0ba1c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:3c50a180a497e9d4c17637066f768ef4b572a55ae7065afa07d38285e0458e6c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:d8c379d28f328b5289ad9e6f0377ec8e186b5ad45491081ff52a9f964d6279ec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:b722d180f3702d05e9c5858cf64dbd6ff7eaf809473164f12185ba706bcc9587
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:50a7c92fc47c375f93702812e7a887580edee45cea140b7f3784b2ca7e9bed49
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:2b20c36578425747f937adfe8dd3b57902b1910140ecc551140bd00b060008be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:770a56f623739cdaf58c92414bea505b062bd87b8c618a67535bc4eeb21d8aea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:1e10741b81e0934a792c84565ad26412cfdef5d8c276bd1735b7d997704674e5