Sign inSign up
Envoy

dhi.io/envoy

Envoy 1.39.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.39-debian-fips-dev, 1.39-debian13-fips-dev, 1.39-fips-dev, 1.39.1-debian-fips-dev, 1.39.1-debian13-fips-dev, 1.39.1-fips-dev

Index digest:

sha256:2e2be88169de89db4239cb86e77c125ea416c89666097230f96857ba211f1df6

Manifest digest:

sha256:01a0f71c24047b7e6ca0ae5c542499ed59964c02cec3c0bb8d053d6bef385825

Size

58.24 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Jan 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy@sha256:df8b326927aa58937d88e9f4385608fb19bce1e64162c15887c34c3e2d0ab87a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy@sha256:33abf55c465566a6993fde881ecf4513cc33e83dd752cf64036677cb7035b6ee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy@sha256:f560071d9df6aabfb9ba15f7e7f246fe61ea208ef51ddd6953dbf4260b8b6737
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy@sha256:331a57679db27ee5a5d89e1d7e18a634b6f7a1d8c680429b5ee94a47e461316c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy@sha256:21255c80025d5550572fbacd88fb7985e009929aaac3af0289ae7f32f0d666c4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy@sha256:c62682aa9dc9f4663f4070cbf207b656973b8ba73a7da3a40e1cedf21160f629
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy@sha256:992cfd9459a1929589a2c6a4a6c0436a71be0550c154e8599e31714b642f0eba
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy@sha256:23b96ce902dffad1020fbb9c79cd5290f2202d7ed44de89497320b9c43c7d8e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy@sha256:e4a7c4ce7d7433273632781f0fa19adb3608c5cf6e6437d04d80142974a4dfe9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy@sha256:a90fc8d10ba9a13962fb77683fb1dbbd237671d59d1fd8e579b86f0a00e74ccc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy@sha256:3b47afa992bbdee17e92cf9485836856285a8a50152eff9093d96bac9555db92
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy@sha256:aebccb698a2a20c4e61b987bf7a0955ebe29c30a93abbbd2c2946d7465cabd52
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy@sha256:8b75be96bac6a8a51e1a9f325be0fe6fc2c491aec9838fe068b3b1d64f1ccf66
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy@sha256:51e975fe53ae1e1f1eac4b13b76da920348eca6c65ffcb1addf76a507128d3b1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy@sha256:3ba6540b54893cccde4d34fb78a3dae4e335f6c78813e4b884b65f80825f588a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy@sha256:d010f1b5f105f133824a0ad2acb98c869fecf49fd5c693128a9a32e08d54468b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy@sha256:43ea6a0a9d7dfc773037a1c57eb3ca37b65d8105aff980a8f9426ad3af474a21