Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.39-debian-fips, 1.39-debian13-fips, 1.39-fips, 1.39.2-debian-fips, 1.39.2-debian13-fips, 1.39.2-fips

Index digest:

sha256:09f653eba25ed8b47be21c5d750b2f9411d44897d3f49ac4f7c593e94df13cb5

Manifest digest:

sha256:c367df04c3e16180b45ed449d5ed48cea720b0fee8ef993fd9117cd1efd64bf0

Size

43.21 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:cb29fa7963a41b506a71b466cb75bd0d94d736c99d24cf9b5b18fa9a03703a76
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:00efb51d997d7ca9022f36004a33048279801dde275c21474db0dc12f5ca89b4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:95ffb246451ea2998fd7b35a28b1c349f363f536e7fcc5f007ca1e24e9f579ee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:4cabed9a725bea73fbb7837876ec1dc1896de39c2cfaaa6b33e7233fe763854a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:12ffe4b7049c966376c7dc8b9561331530a92379a92c60100cdf73caf05cbb64
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:d2a26f6e86fd47569b327554ede22a3ba968302c4efc8e460bd6284b1014f66a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:01ddad882b939e750d6926608ac5e1992ba8c25a93ca70af7a751385535f4fc7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:97775dcc47000f31e866d0e26696b857e27c884a57458b7c37acca1ee588ad4a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:af0078cc63c3aa61f6a4a36ed46e570e4a962a93307e36040962539f97c88c58
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:2b4850fb2c5b891cc40505882dc3c3060b94f94a7ae71588eea7f4a08e2b9c7b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:d5377db1943c49655d205bf9d066e9d0520b749f2be6d4d2018b7b4f69fff8cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:00d19b602a6d0eeb25d1300857cc6a1ac30795be892becbbc81025a90245fa1f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:7b7ee9998b49cb12fde6b0aff1e3b216c049837d0ce6a75a7a5ef9d03d8d8e8d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:452c5ffadecd76a39e54bdc5a9aace6c8400d54926d25dbc4dc40945899ad06b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:c56ae5ec91ed490fb5eafde6862c9bf13e4b49683eceb96bce385eb60b8bcf28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:dcef681e79d6b591e545d15a069cbdff6fc6249d7912813c32d9e1519d1b5817
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:30008204587dc28dd5f1d9d07ccfce58d9c71b73dbdca4b5e9d73015df07b451