Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.38-debian-dev, 1.38-debian13-dev, 1.38-dev, 1.38.6-debian-dev, 1.38.6-debian13-dev, 1.38.6-dev

Index digest:

sha256:d2c2b84039b941df994b5482f11569be7bbdb442ffd06f3d3dad59220453318e

Manifest digest:

sha256:33a17e55e2d2588463ecf956909fec9c30be518aeadd1674c4d0eef07e9d0324

Size

56.05 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:acb47b0379bf50cf6162efa8f3549f7268df269e9f50265060b6127a28274565
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:c53af8afc98a5dfb3b7104260e377771abbcb06b5ad78fcf50f921fe72d44da5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:931fca6dc1eb66a933e9889888948399db307a4a1056aa02045ab46e7205a41d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:b28647f4bd2967fa5474bab8d60477b9f488c03d232e2713e9c8c67292ca3392
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:613a068a4a757b9977da3d13d7e914a4cd3fb6b08a980c048d4eb29db97a61f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:0a3e592858fe69f5768175a532d052fe83f33274019096c6bca296d026aa34ba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:dd810d4578c23c22b6a3a1a6bc6fa08c766d6c60ff07cd0ebb811020795037d9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:eec40b1ec30f84ca4801ca619124b3e2e37fe632f65c75154e9b4b3ecd3d08c4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:f5a807a57f9002935cfa78484f82a0cb9c95c5c7a570dc38883a51b0c38b6ac8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:fa4106ba8610721f58f4bfbe43496a3d9d56bcbed5050bfbd49e120d93e57092
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:2794c57c2bf7a836510f6fdf994a0266de585b959d545f7b0f7fb0cdbfacc31f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:c2ea3071424eb09841a8aeab0046aa11752a40eceb8709d8e56ed8883a3a97f4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:d437c411378935b3714fdd2538809b7e95c1a76459ca8499229e8f2599f048e5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:a9ff27e7d68606011189826e61bd1a08dce64e12e85c54ea51d890dd39e507d0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:c006409b0a211e8d1a4b91f07083307ca8dfdeb8f6aec2f60db8e5b8ba1eaf9f