dhi.io/envoy-gateway
1.7-debian-fips, 1.7-debian13-fips, 1.7-fips, 1.7.5-debian-fips, 1.7.5-debian13-fips, 1.7.5-fips
sha256:e1f378078a2a26afae4bc7ab616c5bf1811e599ef1a1828d76870b2a0d4b99e4
Manifest digest:sha256:f697d1947d3d480cb26fc7d43e9b732ed8d28a8efb46534cd28c799129c8c59c
Size
35.98 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/envoy-gateway:1.7-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/envoy-gateway:1.7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/envoy-gateway@sha256:e7122f56eb0213281bc0e15b8a8108618648bc3453dbdea4edb7501401088d87 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/envoy-gateway@sha256:17561322826de6fc798027e4f23be3f78c23893c1dab6310271eb7ab8dd678c3 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/envoy-gateway@sha256:5b0c54ad090bf69ea858673a2a822ea5bbddfdb2c31a01a6e4aa5e097648b892 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/envoy-gateway@sha256:628dd7f22bc4c7d5e866d8153f7855958ce48be10d4274b05b3c98835f7c0913 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/envoy-gateway@sha256:9175b85b8d9f0a742c15092847b4d6ea2b3544beb3895ca6f05d4e2424225201 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/envoy-gateway@sha256:95552c6db7d953ad4b8d030ef099ab92c5f2a2ec943c01874bc8a46968ea46ea |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/envoy-gateway@sha256:c68fd1f5ba476dc7a36a52f6ee554795da9677cf10f93f986b450b8b3c1a184f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/envoy-gateway@sha256:5da01a574fe520b3aa29b0014c3d5360b4b696e6a5ad4532546557c4cd2d38c4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/envoy-gateway@sha256:93e68477085be0b61fbde8d05f4fab607549a392770e4bf6937f5debd98e1991 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/envoy-gateway@sha256:10282b76733374ea932177343acd91af4800088d5901b6e3b02fc31b4a305c84 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/envoy-gateway@sha256:e1b71cb98a9934ed5bfebacaefd4e5c138bf2c1d894163bab9a1a5f88d6c1242 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/envoy-gateway@sha256:35eeff787c5f55e8923d627ecb6d03e6c94c0f40b2dba4cb6b53e43ceaf02d12 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/envoy-gateway@sha256:9203e13aeb202f8668a1ad084ecbc6da0203209157e572252508d2c8b75b7c25 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/envoy-gateway@sha256:23891a369aa5312316e0caa3033b0625886f5f6153d1ff3947b20c4dc2bf3f14 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/envoy-gateway@sha256:d5ec77eadadf1acdb2063083961bb7887abba5425b574564b82c4d799d79304b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/envoy-gateway@sha256:e4e8856416d5c60eb312498144f79950a71fa5c5e71536458fee55d9aee4d78e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/envoy-gateway@sha256:6bf9a5d2b2f1f4bd9b5d0a67e37129a8b465db7b1aeefa21cf4f1526f8f8080b |