Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.37-debian-fips, 1.37-debian13-fips, 1.37-fips, 1.37.6-debian-fips, 1.37.6-debian13-fips, 1.37.6-fips

Index digest:

sha256:64fe7110fee4b8467989dda09843606d9890d049ce8a1704271d5fc41c7591b4

Manifest digest:

sha256:2cb054824ad490b9d35c213442ebaead65783918d21d472a0afbd91bde7f0b82

Size

38.38 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:6b818a8fcd9583d4a14d37819c1f346e0d16f784de0c6016597c2a7a44f7df02
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:f45e3278d98cb423a7e5ce94708fbf6e7e44981622ce51c88757b3a99dddaf63
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:016604e3af8a7f755f914a83ce3b2f167ea258009859a09380e2ad96aa0bebe1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:565607f5b21ecc35f15bedcbc49ff11a72b581c84c8bbafbb6355c8d7dccf217
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:67d57c9bca792262a8f241bb490ef76b6a77282d388725ce160363ad630dd131
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:ca4ea643a2783b8bf84919b32e0556e10b0f294bf868355c8271d237fc4ddfbb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:a02bf267e896a61deeb95da2d9b3dba7a5d1cafbd520fcf61b92b84f81079ad6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:4271e0adb9629be1ea1c837ab3624de809d7e8b91d25576e9b1e23996cbed8c8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:0d4065076d1f0ad13a98835f97f80a5fe142c12dd769a919df75030fb17247bd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:3061166567f30e0bf51d49e058ca6798e016c9ec0c8267b7a832885f96127fae
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:48d40217c0973ea03c5f7a29eeb138fc4f26f9166a06974346eaeb2f60808637
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:03acc951f6c4c2495b129148f1f92120d0e193ecfb7aabe2b808514ecd9fbe78
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:da54ed702dc027ac1b800db20c9e77b838ca7bf63e986ee89a662bf0244f3ca8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:e23e357d8be2ec4d892dc3bc368142ad1151eea48c3827d99fb019f621dec383
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:322b5cb00eec4722c8a77ca1c5e1eb573934832615ff9f217e02e1dd0045a0ee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:a009cf87c77792cfe7c4f90c17708fae17b62f9a9b0413abb28e34ce73959582
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:f6dc0ac5219cfff7493f6f54a5544dd81dd2c25220e7db42ebaf2eb5c6f88c7b