Sign inSign up
Envoy Contrib

dhi.io/envoy-contrib

Envoy Contrib 1.39.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.39-debian-fips, 1.39-debian13-fips, 1.39-fips, 1.39.1-debian-fips, 1.39.1-debian13-fips, 1.39.1-fips

Index digest:

sha256:00103989428b7a60c605255ac47348dd4325f8ec54d37e7e0e616357e0c5c52d

Manifest digest:

sha256:9c3aff47411704723872b8ed042740b566f0a38697eb2e7e1b3d91b11e6826d4

Size

60.42 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Jul 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-contrib:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-contrib:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-contrib@sha256:2d0f0eef6371496ae44248a9572ac2a5fcb1850ca47847650852d0e9ab3fd4a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-contrib@sha256:ae4c79cd61311fa416901d9d776471733e1763374cf0208a702250fe4a40f30c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-contrib@sha256:360881d66b8bbd4fad985cdfc93133cd4980019741faef8327f0e0d17200eb09
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-contrib@sha256:007bfe6b2e63a3af6d470992c3d6706a39e6390f8572aeb7f042c85495732306
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-contrib@sha256:4d63ef1a9f5e713277e08d7a8a8365208aa513e9ad3652112bbb1ee996ed3297
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-contrib@sha256:7ca28726a8135826868d2342b537ce797e2dee8477e3af8c05394d60c4a58345
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-contrib@sha256:31082fa7119c66105ccda853ad223014ef7c67892d0077a9baec31378e87be8e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-contrib@sha256:0ebabfac65f46019b8178abc162cfbd7472902f12bddedef7a96acb4f3a15de8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-contrib@sha256:3f6b0f949590084c63013145479fe92a9c9c733618d6a2363a2ceeb3a6c2d10f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-contrib@sha256:9dad0cf10697946cb048a9ed4ba98ddeb131dba52ff14b54732225e84bd43a9e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-contrib@sha256:acb03fd8674a4e43005c29306b48d70b49f0c860c7ed518c6999ba67794bccb5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-contrib@sha256:c0e072c9bc9f069760615b329ebd02a80466d910865cc95e3e8452fca4f8ae65
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-contrib@sha256:79015fa3fc2644ab073b379d38440dac58c4c417bca69da182067f919b79b4a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-contrib@sha256:0a7395c2fd61057ff68c22200dc588ab10cece8696b49aee26f11b04bd153f06
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-contrib@sha256:0c08e968e31e7bbe10115fcca9855569fa6db9420c004aecf01dca9cc2858b4d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-contrib@sha256:c0e1ee3b3bf01c12d1359c7fff86385dde03463102f1589a2ce255ebdd93993d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-contrib@sha256:e3ece3c38704d8a7c0ecb02596a7a22009f3d25e412a1c8dc55b3dec1a41cb2d