Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.39-debian-fips-dev, 1.39-debian13-fips-dev, 1.39-fips-dev, 1.39.3-debian-fips-dev, 1.39.3-debian13-fips-dev, 1.39.3-fips-dev

Index digest:

sha256:a772ce08d15de2f4cc81bb0d02b775e65a48e3e706557ec5cdc44f810c7217f2

Manifest digest:

sha256:eb2e70baaf158140fde98a4d1b28a20843c9925c7a4282add3673d8f3568f2ca

Size

58.30 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:52d2e45a3fa1cda8babb3f53b9b4b7ef8cf191cc9dc6fd623190584246873db4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:2de4f4d6709d3f84e7ad617a4a82878aa9c5c65f9a6637e6ce2b297dc52947fd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:467317424e1009375fa370b587333df1a7085586a72cbdab115e15f4788f5849
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:6b0984ae210845ae67a5eba730da9dd0e18e224a433a023ab8efe2736f747992
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:6a23006af71ee3d644edcc1331c752c4a2ff113df787be18286d6f5b6d5fb394
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:728d8aac00b914d652438b487c5273f1441c019edbfba75f08c9999582c0f4ab
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:9bd3db4162dc38b333cb89a7eb5f9e758e1fbd263c444fc8656c2d5c798e5174
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:6da02f389da7d1d1649237afe0d566fd30e39230e7bb9770acfd7e9058f494c9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:3f129670e7c530d87b9a4efffc4bc969b56d3d3551ccddcb3c3039e7e2a56c66
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:ddde77a3ecd7fb612c75257590d8292d51e7d5d8c5d02eb71c5acf94ee18d28e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:e44f24ec7c4fe05ce8a6f11cc72fffadbbd47360c1b59aea6b81635ccab58a4b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:30dd1053ce0389a71b1137c9724efe0f27532c5faea889c9919d57f17f5e58de
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:82e5e2c183c35fd8654e3843435df821429dde3d36a818ea4a2c670711d16002
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:adc9a47681ee61da4e09fc429a549dd341d7f820ab13f7b171d54d0510f36120
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:df9e877319bca6232c35f99ec8c6a640e67c00e542168f02640127d7d5225376
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:0fc063c35daacffbdc4b05fd2e63654be236bed5604e0654af1f390bc5b10199
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:ad5d85625db37b79cb37c17bc684d920a475ba6f5d1fd23d9e14a90fee1f378d