Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.39-debian-dev, 1.39-debian13-dev, 1.39-dev, 1.39.1-debian-dev, 1.39.1-debian13-dev, 1.39.1-dev

Index digest:

sha256:ec3b322cf90b3f3da2af53c12c6e8443c8ffe8cb398242c9f37d5f8ddd6874f0

Manifest digest:

sha256:8caa05030b28a4aed45f23182f0f32981e82c936cdef8457b962ee4c40fc6be1

Size

57.06 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:ee848b0bbb296b10cfcc71db38718c288d130c21ab8e5c98f48e26afeb1d5913
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:42a2c278addb75461a7dedf041b12fd615628153f9bbd41555e4061372e4c6da
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:e1b612383876960f8f1c4a58751c9892770252bd635d3efaf36c2f70f3f00bf7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:5c14fece423d2f3c83e645bcd76cb3542da216ebc285e102157552cecb04fd42
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:2b5205787d7f671c9b3a7ba6e9ae76c58cffc9d9483d26a1b6176f7576da7a07
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:5b3b64cf10419eadbdc69aac488117126c7da959df2f2c3bae7daabff8d9639c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:08e8d062ad2d49b3dff06137b878a2e3e6f58bd9d6c3032ea14c25f56f581cf6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:cc3f83e6844136069e5353e91a9e38383f866f85db9496ff7b4b975135070253
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:df6ce7e7a65302886aa3bbd9f7044f3cb1e9487d051e5b677e934712cca56ba0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:d5fc15998452258ad26c164473bdf6e4094115588b83005c4ea1b9f5d1932c28
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:f6947bab37e284eed11e8306bab2ce4319548557d559da4b4765ec10416ed310
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:668750d7f97826c4cdc1b7f6c88edc717c2e688c6b39d9bc07c8c606af9d894b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:93143cb2e818314cfb9a79ea997231be4f4f1801361825cde1fa853ec6d8c1be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:3d4e5aaa6f1966e6d73804306291533d122fc0b3c6f1634f8a503a118a3601c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:78886e9f82010013d53741361c8de71c01aac90f37de45a77ccf0fe61dffc627