Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.5-debian-fips-dev, 1.8.5-debian13-fips-dev, 1.8.5-fips-dev

Index digest:

sha256:dbca76d5c9e9cb5d3808eb606865450bb8d1a67551c20d4a84813304743418c5

Manifest digest:

sha256:ef7c628f5f36e756560e2c3c135b9d7606dcccd025f779377f24ec812875b50f

Size

77.08 MB

Last pushed

19 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1.8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1.8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:174e81ed580bd1eaa6a1e0e8a53c9c9a56ecfbbb6c6353823ae2c54311b887ab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:39194a342c4719152b5e9c14f49f8387685c7aba67ec0c4808de6d214143e9c2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/envoy-gateway@sha256:4713ed4c05decb5622f4e529c83bb15a5639644ede9aef06e6e19c399f7d532a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:e7f49aaeb1dd850b6fcd947ffd0fda5b4be9016cb724c1fcf8ab3c766811c2ab
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/envoy-gateway@sha256:12f923964891b8097a3ff4575e4b3b225f24feecfe0ec9f23044bb338b946063
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:15be42e09ddb297d4585ab5d19d406854d622033882a9fe4851db6e0981c95fe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:b1e652e2fda5111e0e7603bef73705174698110468897da271d962148c021b8c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:bac289281a5e3d2a03d0097200feffdf92d3553c360efdd6ea9f1c04c3e836d5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:d5cd9e677295d353067c805ccd2b6b8b8c1a71fdb51d229eed9b9da91b1249a0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:3c3e48598e0fd1d12881be2d8ee97b1aa08c574dbce1ce62ab553415f97f7e14
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:7b23273bab66424b4c17fc7e5edfe8852cc11634d0a09a06e8fe5bafff74c150
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:8ebc801abd4a79e26d6bc5f4256657029ce498bf9f60eb63b62684c704d60648
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:4a4244a920bd09a68f3237e56721f5135a812c3c8c7365bfd25d8d4868fe388a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:d93ccc4724559e63e930943d08db36640338bdfa50a4a07bd8c132e834bf5476
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:fc97da09f7f923f93ef89b6448ba52ad220c355f0d0f1f56d26796343d112865
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:a5850b2d9c2d2369360fd1cb0d17242e3f32f081164d9abdcc096cbd4441a58c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:1fe98ec9267b0460b3d062d32d82cb23c626e79967059acb85ac8672e4040afb