Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.39-debian-fips, 1.39-debian13-fips, 1.39-fips, 1.39.3-debian-fips, 1.39.3-debian13-fips, 1.39.3-fips

Index digest:

sha256:7bfdc42d84988173474c30c857682db00f1231e06a734b0236fcbdb2aafe5922

Manifest digest:

sha256:a99afb19b17365794bdb9d4758abaef5792ecdae0e74593e75258ee6d9f635ce

Size

43.25 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:9068828ac50cb5db3c1b3efc1e2e6da2847f479af435b4ee7f451d8dbbdff0cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:c03e9cb82c360b8d0ea68949a770ef48aa811b5acb16c4b2344bbe4912fadb90
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:bb2d6d00edcc3d260b5160a3f8690ee95de625159e946322745acb89214a5cff
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:b94c66396281d333d740cdfdfc91807fb4a2cbc3b07ec5bdaf4d3837628b72f9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:a082434a4582f36c993ca4a5e0f59af94f5e7adf1ac72fea6268193e3e72fab0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:c4b985d7696d8cddb833e86870110fe230ee47c7eb38b0f8a94fb945d8b468b7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:52060408f2f6c0312fc4f6c22a9b61541b1d3dca608afe5cad28cc796736205b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:178cb1abcb95726b50c59cdabc1cfd063621e07b868d561f536a2dd36bc38b30
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:2041cb4c44904931cd5f73fb823dfe32eb2e7c8d15fcc3464b530d329295caa1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:820e6982bcb0f3d41ba68caa85607d5319cb129fd6cda2be488b6d5f07ec065a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:aaf7735c9e2fae2bf37fa65f4e601a02b5f56b22944e690a72f220c2904bec89
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:d461dac6e95ce2c4e800ba181f5b82163fc8d9b4ae0936af393f96a77cbc4b69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:04b6348e117068d8878c31c0fbc43e866a6d8a5bb6596dc192825e1c35f9264b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:2da9ba8b8f794e18d91527c6f73ea9ec5369bf4c447e6bb9ffce238b48351037
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:f38ed673b6d073979996986eb9cfa44885edc9fcfdcab2cf09fdddfd262c47f5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:e425663206b702ca41be53d7b857873ecc7a2d08303589a7121a39a9f0cbc9c4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:264104494e4a96c443ff7cb92b0a341adb81dd69060fd684f98bab24c70e4f81