Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.3-debian-dev, 1.39.3-debian13-dev, 1.39.3-dev

Index digest:

sha256:6f586a2f501094bef7f40463a6ecd10f767d4d7a1d311a55c08b0b0d69d12ad5

Manifest digest:

sha256:17b57161e131d1f7bfa5f1670d3184be994fa6a7439f626e78f97ce85017b478

Size

57.10 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:b474160252d0afe24e36e2608cdda5bfaad7973ddb3cf1e79e67ec7e70640134
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:dbc98754ab08e13cee8245c3f56a00a354831f21869cb5896f652f9b1b4d9adb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:d31f544fe669020f250920ba000fa1bf0ee793d58d4784742dbcbcf6c839c54a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:53c5a220c1974f4a0e4ca8f4f5f24d01789a3e247a6f00412d236ac881a19322
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:d8a305f84a351bed167b68ae52c28242fc6dfcbf020c772de23e1344ef8ebb75
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:a05475fe5262a188eeb62e33f9f78c5cea45ff2e25f23f8f2fd7aa196027d5d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:39723cd35d537b98c5d467db36749c674c2e0f7a690f7fdd90ab6e0a24b1b251
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:e2d67f861e35af8b9dad9b807c425189be53213070644592cd7e14263d02a3c8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:ccedb6f18fbe157b5f50d2f0a2ac9e83652858824f5fc091f84804796113b0cf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:d679b6e8e240c55be5188c849e5db8f0139564c798ad86068edf1a17e94bb1a1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:aea79ba2cc73a6311a2df4c80652d7fda3f24f0b1650454a8ab03886af04e398
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:8ffcb3c9b728d34661aa26d7e92afb7786b237d3b6c9392ffb6d3e846d45d276
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:546a92a5b72e48f263960f93224e76267ea197aa8ca92f9cac52884e65ecfc48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:dec0ee06babe9ac09fc9a56c6c95ed38901bbea4202b23e184558b1542d50704
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:4c64f8d8d5a14d1b6a6107cfbe4d4be8bb4b41929e5869d406a31ce5a5f654e3