Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.38.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.38-debian-fips, 1.38-debian13-fips, 1.38-fips, 1.38.4-debian-fips, 1.38.4-debian13-fips, 1.38.4-fips

Index digest:

sha256:10f3e705260b74cc88c0f317f1f46a0bc93b0fee1cd38c0b428d9ecf018d9988

Manifest digest:

sha256:febca80ec8abe8433e2911f43651cc61fcd322027d2fcd1d0b4974cec0f3018d

Size

42.19 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.38-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.38-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:b7841e65f7450072afd2c1d460714ef8f74bbc008c31ed9e3d13502fae912a8f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:7aaf8c7e0bdac95671f28049d8811d69addf5b8461a295722a47e338957e490f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:7f8ef7ce6a672781367d826ab034db6cb37a65bed46973bac9ce9a738a80348d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:f291fcf48f62018a456abaf0b66f581c91ef697b6f6194c4e1e68e92c14657f4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:df26b8019fe8c07b5b4213bf110ffe467ad82162c48b6fe1b979e6d120b1b4e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:aa3c78869bb0f6c6fff15e57e26cae798332f5f26c76534e44bb030d226dedbf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:9548f81edf11c61efc7eb239815ac7aebcf3123f1bfef4213fe11c52885effb8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:52728140df9c0b772c1d7bc72b030428d9d67ecdac43ab3fb47802a34a4cdddc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:f1db25b36f49d1dc75638256aaa8dfcc3ecafcce9f640686275c9df579805d38
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:1a75b1ead5d35af06884a476830917c94eec4af8424d6637d8d7f6163fde9707
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:49a3eaa88b8e082b130392d539e97583dcb526a4edd394b2c8d187e72e3fab6b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:69ebf5c9b5db632b004ca8cdf2d785aaaaf475c3f8086e130fec51b1fe55bbb4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:f83d3a5d2b0234e516b5f2261c3f01294fcf90cfa1a9421a2ab762e75a65f4a0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:e2db943f8241265f9c2d03768f936c93b0f3febc1dc49f27d045320ae80148c9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:f18291117ba1b447f2b62fa13ae157dbeb9ec78cd3ae9c2b0d4ebbb62a6810ca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:2bed23ca2904136970a6873a03c89049dcd69b06d3f51038fe8d39db27edc0f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:463938a01466d0d82185ba275f5398d15c982121e33679ebf58d8e7fefec9216