Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.38-debian-dev, 1.38-debian13-dev, 1.38-dev, 1.38.5-debian-dev, 1.38.5-debian13-dev, 1.38.5-dev

Index digest:

sha256:2b29af9433e3e13f855c7d9332122d2c0fd00b4acab30359f3d1b45db5622229

Manifest digest:

sha256:181aceb1a6076cd99e28f19ac8e0cd4a4bdf5b2dc6a466041ff08d3361cb7066

Size

56.02 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:e681f453667030d010953001c61dccfe24f66e4f26aa7a6e9791c9934f31b1c9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:2b192255b864d0885699871662694defe3a9462ac435aa638eac2b9bd065db22
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:e16c6ac71912399ef772460c0046bc6dfdc37820d6196b92e92642047628a887
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:2ca5d44be71262dd99590f3b93c57c53ce80e473d5529daa2d753deae39b2240
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:a5ab5068e95db382aaa7d1205a1aec52444d4cff8630241e52179ec6503ba347
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:157a0309b19026abaad1742e3d27a3ca432a5cc5fc98c20de7c5f4c4a23f2d5d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:e2398b06d00c147d0e0f346963c15b6875e3dee21205eba30eeae65e18514d9f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:55b4542ddd2f5cb00fdcfbdda74aa42bed88b41ad28defb618b34ac776faba3e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:37eab961a3cea5d56bad7c526ab1452e344aac6fec30ab2c9d24e8189842ff72
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:bb54d5bd4a4a02af005d8a8817a78c612c330a2c39c99d3d709ef9c14bc4ae8a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:80edac064a764b0655edb3792d141a9df5e9095ae82d6264c29db218bca745cb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:07e65ef4d4c5a169adff313724de3af8832d49d05ea9376d6bf93235b54e7222
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:e7fa050e65f569ec499fa378d0fab0d430f73214cc69acaa72d1066a1dfec212
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:1ba683245394b5a3ab182243ce65f24d4908e37f4e43b924b8d3e29546c42e2f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:70057e5832fdaea9ea5cc177531b7d9b2b3119a95bfb0f8556e953bd71083001