Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.37.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.37-debian-dev, 1.37-debian13-dev, 1.37-dev, 1.37.6-debian-dev, 1.37.6-debian13-dev, 1.37.6-dev

Index digest:

sha256:8e4ff6d264e2c57682651de64eaa249d7ce237a1972b18586fb0c38de9b0b9d5

Manifest digest:

sha256:512967e3008dc1d5fb24505eb5ff972761043c81559e0907ab5965aec731d825

Size

52.36 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
1

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1.37-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1.37-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:d848d2ac4f98f372a838259cd42e953afdfa8cf28c18ba876734edd51ae8a996
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:d5de4ad8da471ea8b4f7ddcebb0fbbba2a0fcc734ad7ac4459ba546472c5f6c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:2e2deeacfce47c0c6c7b452328242463910f825d1fda31e9c8185a4697ed81f5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:d68f96c268504f7df5be0aedf60ffec1cf165671da4f72e37271a1ce8101afb5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:a5b688ed2f5b1c0f77f05e24a950fa314630e07af4cc19ac1b35f1a5f2c49e4d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:5ee4ef6195767f6a2ea66385152567f08ab0956e07f9d0fad034fcbbb3b1dc46
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:6ad2faa87f6370e6d3485303bd0b092c7603536a05d7980916966baae198afca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:446e8b2a38b0fc031f268bd36857e19577caa87f849b5cf3e66676a03ff149cf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:c6f333e6c7a7aaae0cf9578355f0b674981bab6a9ef21966e0e4f00439a1859b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:428e2a0c82f48b7d1f90f9a15b935b2d0a7e4d89b103f43bcfad9c72cb3d3e1b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:4be8910a1c0df5a275ed50822e444e4d887ac45561502febe6166d17548514a2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:87eb6dd4568b57bd8bf05f2c17062c00138b2a5fe89b2551933d5c849ade7e0e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:ef2c88545ad45b201a2616646eca51e72f74c30326d4aca713fb3bc59e0f5956
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:afc47e94cb0f20404b26dbcbcc3130c530012891b832b2b8f19968d97a4b84be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:108d15ceae6a38bc27c622ebdea45fbb16da442392ca1313a90d0859205246a7