Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.39-debian-fips, 1.39-debian13-fips, 1.39-fips, 1.39.1-debian-fips, 1.39.1-debian13-fips, 1.39.1-fips

Index digest:

sha256:6ceab3fc3fd5f222b76c353d0a52da1077e85114a98f7d194a1789242bc77d97

Manifest digest:

sha256:9e8d1d472a31722839ea0e1cfb7270c5e88d08ae385b399cff455e31d8947bb2

Size

43.21 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:413783ef53d64069c0ea1b8be7c3349c5e99b44e40a0461a93af041e11e5279a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:368fc6aefff07948885ae3b410b99bee6db28aacfa95a5a28300cd45f170eeb4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:ecb6ce456e1737e99e35b7581ba08129257078684b5933cf27fe9ea75aeac85f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:897698017e4c6672e04f487e85b3e7a723c3b71e36492d2c5a1043860c8f88a9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:57d091773cbbcf4abf19a67231a48e262c57f13d214c99f0808250f1a8fb35fc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:f75c546880f04d32322f2be85121d8b55b5d488ed69e79318feee2545041cb31
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:8b690021c30a100cd7dc883849ef6428fbcb70bf2ae049e977efd8023247375c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:1b55dab383be31cd9cf789635f25eca4ebcb84fc5623cbfe5ff2bd5bef2d65cc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:49299c01f2bc10b5487ab434fec34be032e33761e09a9edb1bcd4a8a2ce496fa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:e733b32409ee07e8e43a87c2ca4a42c65fdd4e052268e2e06a37f50fa29ebb91
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:6face2eaa6b68061a1baf6927687e7442a364036fa0f08388635740423f2814b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:52e8179f4b52fcbbdbe4f7687789e809dd97d558ecd8e473816c9f6a13b04e26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:d1e9c418512c7bc07f714cd631324689dd8121e7f858dfd3bbfdc29a85ef559b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:d9abf8e53e99bd4866e41062e502bc841bae6886dbe8da351fd8a0d853f0a47a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:e5b938c223f8c4fd24041bed317b4780b8304a70eff7dbf8a9350c031f9e2c91
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:f1d5d950b5f2b9e0aff1c41cbf83c425e2c6cdafe5818c2e55436054b255b60f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:422ed65b4e13f30daf80b250851a60ef2d7ebfa1b14f08b446382b34a9479c42