Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.1-debian-dev, 1.39.1-debian13-dev, 1.39.1-dev

Index digest:

sha256:84552b0ae8bc27396a6e92bc463ae24ec503b7e8d658c3527ea37c20bfa2fbfa

Manifest digest:

sha256:a42cee10aaa326bd845add36c14f60dad7ea3f2c5ccfe36c3e83760e23232e1c

Size

74.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
1

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:ecb1acdf1987062058161c16a35d51cfb9b0df83cce5b3134983c6262f4440c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:c045458271d4c23c5d0f2cbef3d2da17f3ecb3519cc37ebbbc73edb3404d8300
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:882fe912abfdf54fe929d69e82706c48c67bde733494e9f61bb2fc003022fe7a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:7de9e503277161099c9a8dab8cb10ef4ae3d8c21747e10edf26498e12150f644
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:7cd24474ba3a5877d3b6a72c1dbd4d819989aba3485af74ade85d52f88967122
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:3dd27952ab3e0e865bd3064087f16ba6337386783d233550905323dab22e683e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:24db60d7b1796505e23be39f613e864d086f9ea4ff73c1221c152d179a0da0fd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:c363d67ff21be39f74caac34e4d69945bcb7e341ecebe10e3fe884aef04fd05b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:2cbbda245a39a84cf0a47160322c165281b98f9a3fd744065b3ecfa16e16a344
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:f7c6b532bedafb904d3d2e9a179aa7b6b8c0ff054e76ae6015f0da51bff2ae9f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:c3c311f6e2c8102e39dca135c95341eafaf2bff6e03f36ba2996b58c1a2aeae0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:636af0e6ab5f8145aecee9c9735fea29d330e54d46dc4b7bc77a4a68fdf1210f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:94a1e18daa2f5774693e31fd06b5bce4e140069e058796bef7a6f5959775eb61
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:75d39bc79bae418867a4a3deab892768b39ab5dc0e81fe57d4180c57b4586295
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:1c8d60285239dcdf7a218714df9dab0ab46f719421e5ad7c05f60f90cc00dfba