Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.37-debian-fips, 1.37-debian13-fips, 1.37-fips, 1.37.7-debian-fips, 1.37.7-debian13-fips, 1.37.7-fips

Index digest:

sha256:dd2fa7a66329699275089b09e668eae9c00b61cd61600fea0ac70a0acb79c8ea

Manifest digest:

sha256:c86e84e8256c54e426b926d6dc0641e5c77eb5331d9efd6379fc468764f393d9

Size

38.39 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:87dcc0a3d3ded1e073d44e5abe6297caa728aeeae7cb54f7ddd30cc22743e5e8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:a37b02f5e725608724316182bd72119d682a1f8bd8a9533466e1e5c1103353f1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:56a341b2575db48a9a683fc95a105e1a42fc04ff370853ce56f7780550501b7e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:46417d766f13c41f6ecc0d5c6edcaa4315d687b14f38d384088db775b36f7292
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:4c8dc9cc5470afff2eef458b73d65f1e43a19ffc9dbbeff5da01660e58d20efa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:d05da828c12e8157e15865dfa0c62bdac777d4c2806e18cf67772d942566f111
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:376a5151a1cfec34e93f1cd263b2c06386edc556556825740af74f98c903581b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:1d9b83799657b80a5237a6d7a261676ab25e3ec52d37a376abc60afc4f9ceae8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:e6ea89dea667d301c16c9c4cd2805fe85b7f2952453cd5a3046077720ab5cc2a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:1ce91bd43ba8d70e6ff90ca5d5fde159c13943ace1367b923ed537e8ec910c99
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:1d8702d5f1e46d2da42f32c14fff297f3a6ad5439e15851a8fb3ffb6b3d05495
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:c2478c95ea27a52fa7b2edb9f7e651d25c490c06f98f35988312ef0fe259f9ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:474cdf4cd6c5bebbefed977b14afa588ddf70567129201a8450e9ddd3f04b75c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:37f208d2d5d835e0008012f0a9cedbeca2def0bf456f4df67ec716218c7fc845
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:4fe10a56e7a6d509ee43e9f6e9128df63408502db2cf11514d31ab50263b99fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:2eec5facb2df9ea0ce7136bd6bef2364f763234d93be69f3b419b09110a73266
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:571248de2b52b2c1dbcdf41f06d3aba92a280fef7ae81f8c3571bef301f3cd6e