Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.7-debian-fips-dev, 1.7-debian13-fips-dev, 1.7-fips-dev, 1.7.5-debian-fips-dev, 1.7.5-debian13-fips-dev, 1.7.5-fips-dev

Index digest:

sha256:2ed7dd6c34c4fcd0d7bf54f0d2e82fec85cd983aa1ab3eec5b36f44a6280eb00

Manifest digest:

sha256:9d48c057d33343056aa9f1cbf19a543b09a21cdfbf9969174252049605e36ef1

Size

77.24 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:dc40255c4f57ea11559689fa90a00331e5e24f024abe52df560baf24ca6612ef
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:52c01512f478a1521c3510b4cdef2d5fbca69ef77cc336583e510eb9fad04b9d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:3996dad0523ead1cf9f5dc6ea4e4708caefafb108d244a80140e3667223d44bb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:aafcbdfcb1518eef5e5d3d6b7da3cd6aa62418125799c8792fe8080647115792
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:fe314d6255233fefb90b9be115a6dd0a40ef49a2c92c0f92911f1ff4f671deca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:5867f772c859a39d8d90abb342dd1899466c2921c80702a0c802ba9883d151c1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:67d6cf5ac30b423487702a7d72808275738f3aa8dd41f3e4046881294062a956
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:813fbf189a5f0d31748dc39ae12683e4202d3c4c2bd0ca9623a8e6136908fc12
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:563701f3dc15a89f2421fa9b228d99876924ba694b0930176daf42a73ec9172e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:bb7d705197c4fd3dd3c18c8505f775c324dcd8a91747971c054368bf37b02d3d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:769438ff4bc0bee114e6e1a4df84d0181bb3851b18f53ef6e14acf55b665a307
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:99aeda5bcdba37d021d8ec6941519b0b6e357e1b3dc90170d991a0da64c869cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:12ff4889d572ecc3449381345f05d349805fff07f5b67564a4c53e4ffd18fb7c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:3532c3f4e1c2636e32b4441294b5635194cc683cffbb0ff099ca868d9a489537
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:06a868024b76ec523746b56366d00b23a87763d1c65efd1650653b0a6ae59d78
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:373248a0dcdc5116aa5ec899a09e1a7908e32655573b539af949aaf9f49b5b59
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:0026e58bffd46d3717dacdbe4f900fa477f4a0a5b9eb9d5d5a93668127c68376