Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.39-debian-fips-dev, 1.39-debian13-fips-dev, 1.39-fips-dev, 1.39.1-debian-fips-dev, 1.39.1-debian13-fips-dev, 1.39.1-fips-dev

Index digest:

sha256:c615e13b84b6f4e27ac47dc33f3364f86eb77527c4b3e31b9e896dfc0a26d194

Manifest digest:

sha256:eccc29473d922562a78561a88fb1ea1584caecd62daa3df0a5007f574ca5aa90

Size

58.24 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:a77ef4d1116c2a7f3ddd95094d2ef8aea2c83ff03cbbd11d15823b9fe7a5fc90
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:30248e56d43e34bbe802ce135aed52814d2a60c4a6386042f4a594647f299e73
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:97dc2b66ff6feeb7458436faf70c73c2f851ca74a3aaaf09857a6ec15ed1dcdb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:3d87a2166c02be6550c4ba070d613472eae5e8d64fd9e7c156e507c52c5844ca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:98e605e7b4327d9a58298b47b185568fd962a6f1f4bd9a85f6490c6263c34aae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:140f6ddacd64d730da7b38485ba5fa6b683b1d93704a80d834ff408bcb6c8434
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:0e7167a79fe7dd69d785b4de85c957eb0050a5d3db2962df36987f3ff241ced3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:fc4d8420e3159cd76c4951c2c973232e885120a1d9e4cdd3d64c9537e5b3d6b9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:a0d09907bcaaefad04a5b86606edf03d15e75a41af7e6aa3eeacf8037387ca12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:2de2ec5c22a4023a523b7628d99c7603624c42f85eb2a55f2c76bf34bd98c641
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:178359738e94ed9334376e6b02e59acf2fa2737f95985cf1a1b1ede901a78f5c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:e732ccf5eb509ca8b71d87676f99a305b9414ab4a067122f7c5bea4c48f693a4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:db7fed5e610bb6cf7888b5f56eab98f9cb7b1889067a4383a8d150833c7b7335
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:9a23876ac544d1fea6862a2eee22d422e24a7d6d8073e3d8a97f4839e4ee6778
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:3c7915141c6f6b53064e860906252d6884e8c15706ce2530d8dc0d43c2a774be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:1392725a2ce575b1690f6150e8ef6cd6c30c1ccae78424354699f717b134f098
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:d351d6733c6b75b099fb18eb6225fec85e97daefbab2acac48d6c4dd5b1f55b6