Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.9-debian-fips-dev, 1.9-debian13-fips-dev, 1.9-fips-dev, 1.9.1-debian-fips-dev, 1.9.1-debian13-fips-dev, 1.9.1-fips-dev

Index digest:

sha256:02501d38b965cc8c245364d6ecf8c21220340981a01fc7c9e290f14d2e2db3aa

Manifest digest:

sha256:5bd190765a4f05155d65277175d7138f1fccc282b7b73b0fca2b7b3500a33c67

Size

77.32 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:e0f3ce7dbf8acded3681e769e14aa5a75e606ca250c17d05428171779ff02a04
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:5c4a477404fcaf7bb5b48ea6c41d6a5ffb8b02fbdd0ee313672a958dfdd82cc2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:7a755dd72d432c47bead9c3ae9f1ce46b69443b2fae172460029a1f017874665
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:84365c528dfdcd5c35108515a363f8c9b588ccfe249e94ae3c786b4398f9a4e4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:f9471edd8273ec8c8fdedc9a494c58628d26683be599e3033c13215e5d3e57b5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:de1c90355e033d6ef55f92e5735b4d3f034598dc28ce07c3e6203d758f2ea4a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:3f471a6c2cea573af21c0d9589c3f6436802587e19147b8ae413969e7fdbcec4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:89e24fa14cedaee8ad1c8f1c90e3f99d742ba9ab44734a4355c8de16203b84a2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:0b226737c20b1ebeef12d0234ba552c0f98588b5e25a7b8fb4e86ba56b02405c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:1289bb89885c6883074963bc7a2d0172d44bcf2552918a859f90b6aef5e34cc7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:063169c77e473eb558867d16ca9c68025792f4ecce5056d8fefde6aa10c7bb51
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:10b54d5cda8140ebd996ee2706d5b0d153d7d1c071f8cb42349cc8fe81c56940
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:1bbcc1074aee135ed32f0fd44dba3d7c44df3fec54b088c3014c68dbcbdfd750
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:70637627bcdde60ba6c37ac12f64bdc6c57a9458a125a03495c510c72b1788a4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:b8ab1a3a66d9c730d9e7a3b1efc9c2b29af9439af5762d376008ed36eeafaca4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:a90ffd60a7a7a9ef64cb03bf73cace5347155594a5aca03e963d484397f02fcb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:aeb4c75d9cf9e170105b26938b5baa91b937fb0d0afd208bd0418e5d7c685aa8