Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.38-debian-fips-dev, 1.38-debian13-fips-dev, 1.38-fips-dev, 1.38.4-debian-fips-dev, 1.38.4-debian13-fips-dev, 1.38.4-fips-dev

Index digest:

sha256:8cd7a98b1d1b7f7e8f715902014f060f123d006be00aa413fa6038e8b4a14702

Manifest digest:

sha256:3eff0900efc0af103e5f5fa8373f58df38ecd39fa4b8627cc4cfd13f1e1a0cba

Size

57.23 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:cb1afd5855af7d93f743121dc882310ea86983230fdf8fa88fc413b23747749c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:a17932767b74187f77d4e339303e96e8a99c51f68f9bd912729f8978501e7136
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:4e6b556dedd230983a206eb1fe1136b74477212837dc537a02b57b5b2d738598
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:b4abe4f88d46be9f23561e0a41ad31d625716f66c341a7a08987e80ea0c79880
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:7bd1ae0cdc68580b2c3e5a8e9ef2f36865462e969280a19e52e8adbac68913a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:7fedd18d5daceb65326aed13afa9047eb5d11d127e8f1be29afb29843d94766d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:3880f5006758a31a4e17a3b8691a417e45a9e37d80ce521b2b43c28817021152
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:17365dedf3fe5f23cae2b573c2b5401bab05fd2af679a935b8a0e17328b018dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:fadb6966699920c11de45b5caab3d5972a493bc587f08499e55a7b3134e5c72d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:509a7252dd368f8603abdab49f38ac1c41365508b4de5fa12536511178722513
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:b8ae90f7aaee8303fd6ffbec648c82d8d48a074a000571e5dc1839da70aa886e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:1f6d67dec3b5d85df1005eb3e53c465462cfbdd8c697c7f41efc5919b706fd78
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:7e5057aa9facecacebdfdbb9d2af545cc4099dc12be292aab4194887a4ec9e11
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:57980c08838d9bd3e0341b18c4f606aba5602c22d54fafd085bd573e56959b87
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:d62a56049cbfac0470f2fe721e52d9e45d50a08c2ff99a2acfcc1005b81a59a9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:dbb4caf374eaa55696caf004ccaf2ac70ff549e3b51824eff4648164629a38ad
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:9d2ca1f27a65710acb99112e37c572efa2e45c467c06de8e981f2db8ba0aacae