Sign inSign up
Envoy Gateway

dhi.io/envoy-gateway

Envoy Gateway 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.9-debian-dev, 1.9-debian13-dev, 1.9-dev, 1.9.2-debian-dev, 1.9.2-debian13-dev, 1.9.2-dev

Index digest:

sha256:805443d90d1b47ee4b806b3633775e6046879f895b9adb45b5d4bb5a9301bd2f

Manifest digest:

sha256:0e3ea79412767f0713098c2d0904b4e26f689f8e41a2062effbf2d0b2d393457

Size

76.65 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/envoy-gateway:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/envoy-gateway:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/envoy-gateway@sha256:377247ff674a72c46825854e2467c5bdf7f081f6b7c15c27767faec98347eedf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/envoy-gateway@sha256:1ce67c5219c5574142f9fa68baa54d63be2ed25b079f7375cc5fe7fef3429494
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/envoy-gateway@sha256:5d588eabba9aace975ca47275bb52542520bfed1a889c7a9fd2f9b9492f86060
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/envoy-gateway@sha256:a55d9694e4fa8ef340ffa14312598bd3856ddadad908adf007a1fe526e2d672b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/envoy-gateway@sha256:baf992e6851e079f9128aa58bc747de55f960d032d3ead636cad0ef13869f9f4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/envoy-gateway@sha256:fb482849a357ed0b7c4b74eefda82fe635ae08e3fca21f9839335efb4a17385c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/envoy-gateway@sha256:c7b24f981a1c4c487547794a0ba7b58951e83c02f4e8d11885f56fa9c9d564f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/envoy-gateway@sha256:9b305f313dfd83a642767f80372666ffe9077d599d934caa390a387ea7d82158
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/envoy-gateway@sha256:2b5c4056c185b6db4d861272d30c6d76a668fe796e7a349a343b918fe689cd97
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/envoy-gateway@sha256:bb995aa8c591d7007639f7d168d567fe723a10ac0706318e73bee3f17ae558a6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/envoy-gateway@sha256:3a775081b282b90775b542ae4cbce738dc8345f4992ddcc9c09257fb32628018
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/envoy-gateway@sha256:e0bcd95654542fa368f77cf71519df725a2d2c1f803e2b33f69a5875bf3ed6aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/envoy-gateway@sha256:47f773fbb7e4072979087a9d42b2cca76d91360daacdb8f22697687255a8cfb6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/envoy-gateway@sha256:75992218026a834538490aa150eb5dd88fbee1e6743f340545d9860936a925df
SPDX SBOMhttps://spdx.dev/Documentdhi.io/envoy-gateway@sha256:a0071340d38137fba7dd48a5f46a28bfb2aac6ae4e1d987383ceafe7d6a9290c