Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.2-debian-dev, 1.39.2-debian13-dev, 1.39.2-dev

Index digest:

sha256:29b2512df9eeaeac1407f5fc65e638c91c7e54448d8ae564b8a14bcbfbc87040

Manifest digest:

sha256:d1c3bc3a14de6f9fae180506a10d25b7cbee225d48a406eb12f8564532ec9677

Size

57.06 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:ca993bd3bddabddb85e7b230064c8346c15cc1ea0f3b76d7e95ffd06682ed981
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:1fc36110a9ce55b6b9e3c8dc8c659c899b3d06ddf577267ea8d7ffa5118f52c7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:baa7160cbfb93998558dab32b5061f0fbd8e85dd0b61b1408bd6483eafd1b082
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:ea0b26ea948bbd64c3ba481e3a716810d0f01d2e0e7103cb77ecd49962bbcbf1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:e3c00e17fbb9fd5411bfd5cc61e46ff9c09cc970b51b70eba073363fa3f91237
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:56178640898f15f823949a302b9966c7cefc5af93e23d7f124834054b69dfd3b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:d5f95f0d2ae705858a2d7c5020e91331b17a6a5f3b4e6b9d6483cb05942a570b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:c7825629f65c49c0cd7183b8175eac8edb89b5dfa99b302db6f411e3492e801d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:bd11dda3623a9b6c2dd74ef35c22b4c9dc6846b3f983071c1c77279281b098c8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:900abe299ec51a2ee5452a643f6281abf0ccb447b983a691435f16f0c9d55f26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:d53121110fa12832850479d12e3b3c29b1c5a592cf92810def74d53267825625
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:6364f25ab11bd6de15b3b81117aef34c4658f7c2eedc34040028d15d239d654d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:ba3de6bca0524de5f5d87d790509a6428816582541fb7ec78bea1150883b08e5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:9ec2106ea09cc70e151b6a26c1f66901f004756745e17fc0374e78d63dbdffcd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:37eb28b9ae7125dfc9224088c45d608772254c7b5c97306043ed0d99fd72b4ac